The Tomcat Admin interface installed and used by Benchmark is exposed on all interfaces, with weak credentials "admin" (with no password). This exposes the webapp, and the underlying host to total compromise by any attacker on the network.
The Tomcat instance is unhardened, and has various other issues as well.
I suggest the following changes:
- Configure the underlying Tomcat 8 instance to listen only on 127.0.0.1
- Remove the following administrative consoles, which are not required
- /manager
- /host-manager
3) Change the default Tomcat users configured in tomcat-users.xml (or simply remove all users, since they do not appear to be required)
4) Remove sample.war (and the examples folder in its entirety)
5) Remove the installed documentation folder
6) If deploying a Tomcat instance with Benchmark, follow the CIS Tomcat Hardening guidelines.
The Tomcat Admin interface installed and used by Benchmark is exposed on all interfaces, with weak credentials "admin" (with no password). This exposes the webapp, and the underlying host to total compromise by any attacker on the network.
The Tomcat instance is unhardened, and has various other issues as well.
I suggest the following changes:
3) Change the default Tomcat users configured in tomcat-users.xml (or simply remove all users, since they do not appear to be required)
4) Remove sample.war (and the examples folder in its entirety)
5) Remove the installed documentation folder
6) If deploying a Tomcat instance with Benchmark, follow the CIS Tomcat Hardening guidelines.