VMware vSphere 7.0 vCenter Appliance UI Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates ✎ 1
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Content changes 1
- V-256785 Medium check vSphere UI application files must be verified for their integrity.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- VCUI-70-000001
- Vuln IDs
-
- V-256778
- Rule IDs
-
- SV-256778r889333_rule
Checks: C-60453r889331_chk
At the command prompt, run the following command: # xmllint --xpath '/Server/Service/Connector[@port="${http.port}"]/@connectionTimeout' /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: connectionTimeout="300000" If the output does not match the expected result, this is a finding.
Fix: F-60396r889332_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Configure the http <Connector> node with the value: connectionTimeout="300000" Example: <Connector .. connectionTimeout="300000" ..> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- VCUI-70-000002
- Vuln IDs
-
- V-256779
- Rule IDs
-
- SV-256779r889336_rule
Checks: C-60454r889334_chk
At the command prompt, run the following command: # xmllint --xpath '/Server/Service/Connector[@port="${http.port}"]/@maxThreads' /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: maxThreads="800" If the output does not match the expected result, this is a finding.
Fix: F-60397r889335_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Configure each <Connector> node with the value: maxThreads="800" Example: <Connector .. maxThreads="800" ..> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- VCUI-70-000003
- Vuln IDs
-
- V-256780
- Rule IDs
-
- SV-256780r889339_rule
Checks: C-60455r889337_chk
At the command prompt, run the following command: # xmllint --xpath '/Server/Service/Connector[@port="${http.port}"]/@maxPostSize' /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: XPath set is empty If the output does not match the expected result, this is a finding.
Fix: F-60398r889338_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Navigate to each of the <Connector> nodes. Remove any configuration for "maxPostSize". Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- VCUI-70-000004
- Vuln IDs
-
- V-256781
- Rule IDs
-
- SV-256781r889342_rule
Checks: C-60456r889340_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/context.xml | xmllint --xpath '/Context/@useHttpOnly' - Expected result: useHttpOnly="true" If the output does not match the expected result, this is a finding.
Fix: F-60399r889341_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/context.xml Add the following configuration to the <Context> node: useHttpOnly="true" Example: <Context useHttpOnly="true" sessionCookieName="VSPHERE-UI-JSESSIONID" sessionCookiePath="/ui"> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- VCUI-70-000005
- Vuln IDs
-
- V-256782
- Rule IDs
-
- SV-256782r889345_rule
Checks: C-60457r889343_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/server.xml | xmllint --xpath '/Server/Service/Engine/Host/Valve[@className="org.apache.catalina.valves.AccessLogValve"]/@pattern' - Expected result: pattern="%h %{x-forwarded-for}i %l %u %t &quot;%r&quot; %s %b %{#hashedClientId#}s %{#hashedRequestId#}r %I %D" If the output does not match the expected result, this is a finding.
Fix: F-60400r889344_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Ensure the log pattern in the "org.apache.catalina.valves.AccessLogValve" node is set to the following: pattern="%h %{x-forwarded-for}i %l %u %t "%r" %s %b %{#hashedClientId#}s %{#hashedRequestId#}r %I %D" Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- VCUI-70-000006
- Vuln IDs
-
- V-256783
- Rule IDs
-
- SV-256783r889348_rule
Checks: C-60458r889346_chk
At the command prompt, run the following command: # grep StreamRedirectFile /etc/vmware/vmware-vmon/svcCfgfiles/vsphere-ui.json Expected result: "StreamRedirectFile": "%VMWARE_LOG_DIR%/vmware/vsphere-ui/logs/vsphere-ui-runtime.log", If no log file is specified for the "StreamRedirectFile" setting, this is a finding.
Fix: F-60401r889347_fix
Navigate to and open: /etc/vmware/vmware-vmon/svcCfgfiles/vsphere-ui.json Below the last line of the "PreStartCommandArg" block, add or reconfigure the following line: "StreamRedirectFile": "%VMWARE_LOG_DIR%/vmware/vsphere-ui/logs/vsphere-ui-runtime.log", Restart the appliance for changes to take effect.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- VCUI-70-000007
- Vuln IDs
-
- V-256784
- Rule IDs
-
- SV-256784r889351_rule
Checks: C-60459r889349_chk
At the command prompt, run the following command: # find /var/log/vmware/vsphere-ui/ -xdev -type f -a '(' -perm -o+w -o -not -user vsphere-ui -o -not -group users -a -not -group root ')' -exec ls -ld {} \; If any files are returned, this is a finding.
Fix: F-60402r889350_fix
At the command prompt, run the following commands: # chmod 644 /storage/log/vmware/vsphere-ui/logs/<file> # chown vsphere-ui:users /storage/log/vmware/vsphere-ui/logs/<file> Note: Substitute <file> with the listed file.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- VCUI-70-000008
- Vuln IDs
-
- V-256785
- Rule IDs
-
- SV-256785r918981_rule
Checks: C-60460r918980_chk
At the command prompt, run the following command: # rpm -V vsphere-ui|grep "^..5......"|grep -v -E "\.prop|\.pass|\.xml|\.json" If there is any output, this is a finding.
Fix: F-60403r889353_fix
Reinstall the vCenter Server Appliance (VCSA) or roll back to a snapshot. VMware does not support modifying the vSphere UI installation files manually.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- VCUI-70-000009
- Vuln IDs
-
- V-256786
- Rule IDs
-
- SV-256786r889357_rule
Checks: C-60461r889355_chk
At the command prompt, run the following command: # diff <(find /usr/lib/vmware-vsphere-ui/plugin-packages/vsphere-client/plugins -type f|sort) <(rpm -ql vsphere-ui|grep "/usr/lib/vmware-vsphere-ui/plugin-packages/vsphere-client/plugins/"|sort) If there is any output, this indicates a vSphere UI plugin is present that does not ship with the vCenter Server Appliance (VCSA). If this plugin is not known and approved, this is a finding.
Fix: F-60404r889356_fix
For every unauthorized plugin returned by the check, run the following command: # rm <file>
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000010
- Vuln IDs
-
- V-256787
- Rule IDs
-
- SV-256787r889360_rule
Checks: C-60462r889358_chk
At the command prompt, run the following command: # grep UserDatabaseRealm /usr/lib/vmware-vsphere-ui/server/conf/server.xml If the command produces any output, this is a finding.
Fix: F-60405r889359_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Remove all <Realm> nodes. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000011
- Vuln IDs
-
- V-256788
- Rule IDs
-
- SV-256788r889363_rule
Checks: C-60463r889361_chk
At the command prompt, run the following command: # grep "package.access" /usr/lib/vmware-vsphere-ui/server/conf/catalina.properties Expected result: package.access=sun.,org.apache.catalina.,org.apache.coyote.,org.apache.jasper.,org.apache.tomcat. If the output of the command does not match the expected result, this is a finding.
Fix: F-60406r889362_fix
Navigate to and open: /usr/lib/vmware-sso/vmware-sts/conf/catalina.properties Ensure the "package.access" line is configured as follows: package.access=sun.,org.apache.catalina.,org.apache.coyote.,org.apache.jasper.,org.apache.tomcat. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000012
- Vuln IDs
-
- V-256789
- Rule IDs
-
- SV-256789r889366_rule
Checks: C-60464r889364_chk
At the command prompt, run the following command: # grep -En '(x-csh<)|(x-sh<)|(x-shar<)|(x-ksh<)' /usr/lib/vmware-vsphere-ui/server/conf/web.xml If the command produces any output, this is a finding.
Fix: F-60407r889365_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Remove all of the following nodes lines: <mime-type>application/x-csh</mime-type> <mime-type>application/x-shar</mime-type> <mime-type>application/x-sh</mime-type> <mime-type>application/x-ksh</mime-type> Restart the service with the following command: # vmon-cli --restart vsphere-ui Note: Delete the entire mime-mapping node for the target mime-type. Example: <mime-mapping> <extension>sh</extension> <mime-type>application/x-sh</mime-type> </mime-mapping>
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000013
- Vuln IDs
-
- V-256790
- Rule IDs
-
- SV-256790r889369_rule
Checks: C-60465r889367_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '/web-app/servlet-mapping/servlet-name[text()="jsp"]/parent::servlet-mapping' - Expected result: <servlet-mapping> <servlet-name>jsp</servlet-name> <url-pattern>*.jsp</url-pattern> <url-pattern>*.jspx</url-pattern> </servlet-mapping> If the .jsp and .jspx file url-patterns are not configured as in the expected result, this is a finding.
Fix: F-60408r889368_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Navigate to and locate the mapping for the JSP servlet. It is the <servlet-mapping> node that contains <servlet-name>jsp</servlet-name>. Configure the <servlet-mapping> node to look like the code snippet below: <!-- The mappings for the JSP servlet --> <servlet-mapping> <servlet-name>jsp</servlet-name> <url-pattern>*.jsp</url-pattern> <url-pattern>*.jspx</url-pattern> </servlet-mapping> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000014
- Vuln IDs
-
- V-256791
- Rule IDs
-
- SV-256791r889372_rule
Checks: C-60466r889370_chk
At the command prompt, run the following command: # grep -n 'webdav' /usr/lib/vmware-vsphere-ui/server/conf/web.xml If the command produces any output, this is a finding.
Fix: F-60409r889371_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml. Find the <servlet-name>webdav</servlet-name> node and remove the entire parent <servlet> block. Find the <servlet-name>webdav</servlet-name> node and remove the entire parent <servlet-mapping> block. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000015
- Vuln IDs
-
- V-256792
- Rule IDs
-
- SV-256792r889375_rule
Checks: C-60467r889373_chk
At the command prompt, run the following command: # grep JreMemoryLeakPreventionListener /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: <Listener className="org.apache.catalina.core.JreMemoryLeakPreventionListener"/> If the output of the command does not match the expected result, this is a finding.
Fix: F-60410r889374_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Navigate to the <Server> node. Add '<Listener className="org.apache.catalina.core.JreMemoryLeakPreventionListener"/>' to the <Server> node. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- VCUI-70-000016
- Vuln IDs
-
- V-256793
- Rule IDs
-
- SV-256793r889378_rule
Checks: C-60468r889376_chk
At the command prompt, run the following command: # find /usr/lib/vmware-vsphere-ui/server/static/ -type l -ls If the command produces any output, this is a finding.
Fix: F-60411r889377_fix
At the command prompt, run the following command: Note: Replace <file_name> for the name of any files that were returned. unlink <file_name> Repeat the command for each file that was returned.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- VCUI-70-000017
- Vuln IDs
-
- V-256794
- Rule IDs
-
- SV-256794r889381_rule
Checks: C-60469r889379_chk
At the command prompt, run the following command: # find /usr/lib/vmware-vsphere-ui/server/lib /usr/lib/vmware-vsphere-ui/server/conf -xdev -type f -a '(' -perm -o+w -o -not -user root -o -not -group root ')' -exec ls -ld {} \; If the command produces any output, this is a finding.
Fix: F-60412r889380_fix
At the command prompt, run the following commands: # chmod o-w <file> # chown root:root <file> Repeat the commands for each file that was returned.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001664
- Version
- VCUI-70-000018
- Vuln IDs
-
- V-256795
- Rule IDs
-
- SV-256795r889384_rule
Checks: C-60470r889382_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/context.xml | xmllint --xpath '/Context/@sessionCookiePath' - Expected result: sessionCookiePath="/ui" If the output does not match the expected result, this is a finding.
Fix: F-60413r889383_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/context.xml Add the following configuration to the <Context> node: sessionCookiePath="/ui" Example: <Context useHttpOnly="true" sessionCookieName="VSPHERE-UI-JSESSIONID" sessionCookiePath="/ui"> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- VCUI-70-000019
- Vuln IDs
-
- V-256796
- Rule IDs
-
- SV-256796r889387_rule
Checks: C-60471r889385_chk
At the command line, run the following command: # grep EXIT_ON_INIT_FAILURE /usr/lib/vmware-vsphere-ui/server/conf/catalina.properties Expected result: org.apache.catalina.startup.EXIT_ON_INIT_FAILURE=true If the output of the command does not match the expected result, this is a finding.
Fix: F-60414r889386_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/catalina.properties Add or change the following line: org.apache.catalina.startup.EXIT_ON_INIT_FAILURE=true Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001094
- Version
- VCUI-70-000020
- Vuln IDs
-
- V-256797
- Rule IDs
-
- SV-256797r889390_rule
Checks: C-60472r889388_chk
At the command prompt, run the following command: # xmllint --xpath '/Server/Service/Connector[@port="${http.port}"]/@acceptCount' /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: acceptCount="300" If the output does not match the expected result, this is a finding.
Fix: F-60415r889389_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Navigate to the <Connector> configured with port="${http.port}". Add or change the following value: acceptCount="300" Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-10
- Severity
- M
- CCI
- CCI-001310
- Version
- VCUI-70-000021
- Vuln IDs
-
- V-256798
- Rule IDs
-
- SV-256798r889393_rule
Checks: C-60473r889391_chk
At the command prompt, run the following command: # xmllint --xpath '/Server/Service/Connector[@port="${http.port}"]/@URIEncoding' /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: URIEncoding="UTF-8" If the output does not match the expected result, this is a finding.
Fix: F-60416r889392_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Navigate to each of the <Connector> nodes. Configure each <Connector> node with the value 'URIEncoding="UTF-8"'. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- VCUI-70-000022
- Vuln IDs
-
- V-256799
- Rule IDs
-
- SV-256799r889396_rule
Checks: C-60474r889394_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '/web-app/welcome-file-list' - Expected result: <welcome-file-list> <welcome-file>index.html</welcome-file> <welcome-file>index.htm</welcome-file> <welcome-file>index.jsp</welcome-file> </welcome-file-list> If the output of the command does not match the expected result, this is a finding.
Fix: F-60417r889395_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Add the following section under the <web-apps> node: <welcome-file-list> <welcome-file>index.html</welcome-file> <welcome-file>index.htm</welcome-file> <welcome-file>index.jsp</welcome-file> </welcome-file-list> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- VCUI-70-000023
- Vuln IDs
-
- V-256800
- Rule IDs
-
- SV-256800r889399_rule
Checks: C-60475r889397_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '//param-name[text()="listings"]/parent::init-param' - Expected result: <init-param> <param-name>listings</param-name> <param-value>false</param-value> </init-param> If the output of the command does not match the expected result, this is a finding.
Fix: F-60418r889398_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Set the <param-value> to "false" in all <param-name>listing</param-name> nodes. Note: The setting should look like the following: <init-param> <param-name>listings</param-name> <param-value>false</param-value> </init-param> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- VCUI-70-000024
- Vuln IDs
-
- V-256801
- Rule IDs
-
- SV-256801r889402_rule
Checks: C-60476r889400_chk
At the command prompt, run the following command: # xmllint --xpath '/Server/Service/Connector[@port="${http.port}"]/@server' /usr/lib/vmware-vsphere-ui/server/conf/server.xml Expected result: server="Anonymous" If the output does not match the expected result, this is a finding.
Fix: F-60419r889401_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Navigate to each of the <Connector> nodes. Configure each <Connector> node with 'server="Anonymous"'. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- VCUI-70-000025
- Vuln IDs
-
- V-256802
- Rule IDs
-
- SV-256802r889405_rule
Checks: C-60477r889403_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/server.xml | xmllint --xpath '/Server/Service/Engine/Host/Valve[@className="org.apache.catalina.valves.ErrorReportValve"]' - Expected result: <Valve className="org.apache.catalina.valves.ErrorReportValve" showServerInfo="false" showReport="false"/> If the output of the command does not match the expected result, this is a finding.
Fix: F-60420r889404_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Locate the following Host block: <Host ...> ... </Host> Inside this block, remove any existing Valve with className="org.apache.catalina.valves.ErrorReportValve" and add the following: <Valve className="org.apache.catalina.valves.ErrorReportValve" showServerInfo="false" showReport="false"/> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- VCUI-70-000026
- Vuln IDs
-
- V-256803
- Rule IDs
-
- SV-256803r889408_rule
Checks: C-60478r889406_chk
At the command prompt, run the following command: # grep allowTrace /usr/lib/vmware-vsphere-ui/server/conf/server.xml If "allowTrace" is set to "true", this is a finding. If no line is returned, this is not a finding.
Fix: F-60421r889407_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Navigate to and locate 'allowTrace="true"'. Remove the 'allowTrace="true"' setting. Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- VCUI-70-000027
- Vuln IDs
-
- V-256804
- Rule IDs
-
- SV-256804r889411_rule
Checks: C-60479r889409_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '//param-name[text()="debug"]/parent::init-param' - Expected result: <init-param> <param-name>debug</param-name> <param-value>0</param-value> </init-param> If the output of the command does not match the expected result, this is a finding.
Fix: F-60422r889410_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Navigate to all <debug> nodes that are not set to "0". Set the <param-value> to "0" in all <param-name>debug</param-name> nodes. Note: The debug setting should look like the following: <init-param> <param-name>debug</param-name> <param-value>0</param-value> </init-param> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- VCUI-70-000028
- Vuln IDs
-
- V-256805
- Rule IDs
-
- SV-256805r889414_rule
Checks: C-60480r889412_chk
At the command prompt, run the following command: # rpm -V vsphere-ui|grep serviceability.xml|grep "^..5......" If the command returns any output, this is a finding.
Fix: F-60423r889413_fix
Reinstall the VCSA or roll back to a snapshot. VMware does not support modifying the vSphere UI installation files manually.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- VCUI-70-000029
- Vuln IDs
-
- V-256806
- Rule IDs
-
- SV-256806r889417_rule
Checks: C-60481r889415_chk
At the command prompt, run the following command: # rpm -V VMware-visl-integration|grep vmware-services-vsphere-ui.conf|grep "^..5......" If the command returns any output, this is a finding.
Fix: F-60424r889416_fix
Navigate to and open: /etc/vmware-syslog/vmware-services-vsphere-ui.conf Create the file if it does not exist. Set the contents of the file as follows: input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/vsphere_client_virgo.log" Tag="ui-main" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/changelog.log" Tag="ui-changelog" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/dataservice.log" Tag="ui-dataservice" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/apigw.log" Tag="ui-apigw" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/equinox.log" Tag="ui-equinox" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/eventlog.log" Tag="ui-eventlog" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/httpRequest.log" Tag="ui-httpRequest" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/opid.log" Tag="ui-opid" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/osgi.log" Tag="ui-osgi" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/performanceAudit.log" Tag="ui-performanceAudit" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/plugin-medic.log" Tag="ui-plugin-medic" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/threadmonitor.log" Tag="ui-threadmonitor" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/threadpools.log" Tag="ui-threadpools" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/vspheremessaging.log" Tag="ui-vspheremessaging" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/vsphere-ui-rpm.log" Tag="ui-rpm" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/vsphere-ui-runtime*" Tag="ui-runtime" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/logs/access/localhost_access*" Tag="ui-access" Severity="info" Facility="local0") input(type="imfile" File="/var/log/vmware/vsphere-ui/vsphere-ui-gc*" Tag="ui-gc" Severity="info" Facility="local0") input(type="imfile" File="/var/log/firstboot/vsphere_ui_firstboot*" Tag="ui-firstboot" Severity="info" Facility="local0")
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-001762
- Version
- VCUI-70-000030
- Vuln IDs
-
- V-256807
- Rule IDs
-
- SV-256807r889420_rule
Checks: C-60482r889418_chk
At the command prompt, run the following command: # grep '\.port' /usr/lib/vmware-vsphere-ui/server/conf/catalina.properties Expected result: http.port=5090 proxy.port=443 If the output of the command does not match the expected result, this is a finding.
Fix: F-60425r889419_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/catalina.properties Navigate to the ports specification section. Set the vSphere UI port specifications according to the shipping configuration as follows: http.port=5090 proxy.port=443 Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- VCUI-70-000031
- Vuln IDs
-
- V-256808
- Rule IDs
-
- SV-256808r889423_rule
Checks: C-60483r889421_chk
At the command prompt, run the following commands: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/server.xml | sed '2 s/xmlns=".*"//g' | xmllint --xpath '/Server/@port' - Expected result: port="${shutdown.port}" If the output does not match the expected result, this is a finding. # grep shutdown /etc/vmware/vmware-vmon/svcCfgfiles/vsphere-ui.json|sed -e 's/^[ ]*//' Expected result: "-Dshutdown.port=-1", If the output does not match the expected result, this is a finding.
Fix: F-60426r889422_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/server.xml Ensure the server port is disabled: <Server port="${shutdown.port}"> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- VCUI-70-000032
- Vuln IDs
-
- V-256809
- Rule IDs
-
- SV-256809r889426_rule
Checks: C-60484r889424_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '/web-app/session-config/cookie-config/secure' - Expected result: <secure>true</secure> If the output of the command does not match the expected result, this is a finding.
Fix: F-60427r889425_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Navigate to the /<web-apps>/<session-config>/<cookie-config> node and configure it as follows. <cookie-config> <http-only>true</http-only> <secure>true</secure> </cookie-config> Restart the service with the following command: # vmon-cli --restart vsphere-ui
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- VCUI-70-000033
- Vuln IDs
-
- V-256810
- Rule IDs
-
- SV-256810r889429_rule
Checks: C-60485r889427_chk
At the command prompt, run the following command: # xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '/web-app/servlet/servlet-name[text()="default"]/../init-param/param-name[text()="readonly"]/../param-value[text()="false"]' - Expected result: XPath set is empty If the output of the command does not match the expected result, this is a finding.
Fix: F-60428r889428_fix
Navigate to and open: /usr/lib/vmware-vsphere-ui/server/conf/web.xml Navigate to the /<web-apps>/<servlet>/<servlet-name>default</servlet-name>/ node and remove the following node: <init-param> <param-name>readonly</param-name> <param-value>false</param-value> </init-param> Restart the service with the following command: # vmon-cli --restart vsphere-ui