Details
Tomcat provides documentation and other directories in the default installation which do not serve a production use. These files must be deleted.
Solution
From the Tomcat server OS type the following command:
sudo rm -rf $CATALINA_BASE/webapps/docs
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Unix.
References
- 800-53|CM-7a.
- CAT|III
- CCI|CCI-000381
- CSCv6|9.1
- Rule-ID|SV-222960r615938_rule
- STIG-ID|TCAT-AS-000580
- STIG-Legacy|SV-111445
- STIG-Legacy|V-102503
- Vuln-ID|V-222960