V-204744
Application Server Security Requirements Guide
Title
The application server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.
Description
<VulnDiscussion>Some networking protocols may not meet organizational security requirements to protect data and components. Application servers natively host a number of various features, such as management interfaces, httpd servers and message queues. These features all run on TCPIP ports. This creates the potential that the vendor may choose to utilize port numbers or network services that have been deemed unusable by the organization. The application server must have the capability to both r...
Fix Text (Documentation Requirement)
Configure the application server to disable any ports or protocols that are prohibited by the PPSM CAL and vulnerability assessments.