Rule ID
SV-241720r879806_rule
Version
V1R2
CCIs
CCI-002385
An attacker has at least two reasons to stop a web server. The first is to cause a DoS, and the second is to put in place changes the attacker made to the web server configuration. As a Tomcat derivative, tc Server uses a port (defaults to 8005) as a shutdown port. If enabled, a shutdown signal can be sent to tc Server through this port. To ensure availability, the shutdown port should be disabled.
At the command prompt, execute the following command: grep base.shutdown.port /usr/lib/vmware-casa/casa-webapp/conf/catalina.properties If the value of "base.shutdown.port" is not set to "-1" or is missing, this is a finding.
Navigate to and open /usr/lib/vmware-casa/casa-webapp/conf/catalina.properties. Navigate to the "base.shutdown.port" setting. Add the setting 'base.shutdown.port=-1' to the "catalina.properties" file.