Java permissions must be set for hosted applications.

From JBoss EAP 6.3 Security Technical Implementation Guide

Part of SRG-APP-000033-AS-000024

Associated with: CCI-000213

SV-76707r1_rule Java permissions must be set for hosted applications.

Vulnerability discussion

The Java Security Manager is a java class that manages the external boundary of the Java Virtual Machine (JVM) sandbox, controlling how code executing within the JVM can interact with resources outside the JVM.The JVM requires a security policy in order to restrict application access. A properly configured security policy will define what rights the application has to the underlying system. For example, rights to make changes to files on the host system or to initiate network sockets in order to connect to another system.

Check content

Obtain documentation from the admin that identifies the applications hosted on the JBoss server as well as the corresponding rights the application requires. For example, if the application requires network socket permissions and file write permissions, those requirements should be documented. 1. Identify the JBoss installation as either domain or standalone and review the relevant configuration file. For domain installs: JBOSS_HOME/bin/domain.conf For standalone installs: JBOSS_HOME/bin/standalone.conf 2. Identify the location and name of the security policy by reading the JAVA_OPTS flag -Djava.security.policy= where will indicate name and location of security policy. If the application uses a policy URL, obtain URL and policy file from system admin. 3. Review security policy and ensure hosted applications have the appropriate restrictions placed on them as per documented application functionality requirements. If the security policy does not restrict application access to host resources as per documented requirements, this is a finding.

Fix text

Configure the Java security manager to enforce access restrictions to the host system resources in accordance with application design and resource requirements.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer