V-204761
SV-204761r1137579_rule
CAT II
The application server must separate hosted application functionality from application server management functionality.
From: Application Server Security Requirements Guide (V4R4)
Description
<VulnDiscussion>The application server consists of the management interface and hosted applications. By separating the management interface from hosted applications, the user must authenticate as a privileged user to the management interface before being presented with management functionality. This prevents nonprivileged users from having visibility to functions not available to the user. By limiting visibility, a compromised nonprivileged account does not offer information to the attacker to functionality and information needed to further the attack on the application server.
Application server management functionality includes functions necessary to administer the application server and requires privileged access via one of the accounts assigned to a management role. The hosted application and hosted application functionality consists of the assets needed for the application to function, such as the business logic, databases, user authentication, etc.
This requirement also applies to Zero Trust initiatives.
The separation of application server administration functionality from hosted application functionality is either physical or logical and is accomplished by using different computers, different central processing units, different instances of the operating system, network addresses, network ports, or combinations of these methods, as appropriate.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
Check Procedure
Review the application server documentation and configuration to verify that the application server separates admin functionality from hosted application functionality.
If the application server does not separate application server admin functionality from hosted application functionality, this is a finding.
Fix Text
Configure the application server so that admin management functionality and hosted applications are separated.
CCI Reference
CCI-001082- Created
- 2026-04-07 20:08:11
- Last Updated
- 2026-04-07 20:08:11