Rule ID
SV-256714r888733_rule
Version
V1R2
CCIs
CCI-001749
VMware ships Lookup Service on the vCenter Server Appliance (VCSA) with one webapp. Any other path is potentially malicious and must be removed.
At the command prompt, run the following command: # ls -A /usr/lib/vmware-lookupsvc/webapps/*.war Expected result: /usr/lib/vmware-lookupsvc/webapps/ROOT.war If the output does not match the expected result, this is a finding.
For each unexpected directory returned in the check, run the following command: # rm /usr/lib/vmware-lookupsvc/webapps/<NAME> Restart the service with the following command: # vmon-cli --restart lookupsvc