V-222665
Application Security and Development Security Technical Implementation Guide
Title
The designer must ensure uncategorized or emerging mobile code is not used in applications.
Description
<VulnDiscussion>By definition, mobile code is software obtained from remote systems outside the enclave boundary, transferred across a network, and then downloaded and executed on a local system without explicit installation or execution by the recipient. For a complete list of mobile code categorizations, refer to the overview document included with this STIG. Categorized mobile code includes but is not limited to: - ActiveX - Windows Scripting Host when used as mobile code - Unix Shell Scr...
Fix Text (Documentation Requirement)
Remove uncategorized or emerging mobile code from the application or obtain a waiver and risk acceptance to operate.