DISA STIGS Viewer

JBoss QuickStarts must be removed.

Overview

Finding ID Version Rule ID IA Controls Severity
V-213521 JBOS-AS-000235 SV-213521r960963_rule   Medium
Description
JBoss QuickStarts are demo applications that can be deployed quickly. Demo applications are not written with security in mind and often open new attack vectors. QuickStarts must be removed.
STIG Date
JBoss Enterprise Application Platform 6.3 Security Technical Implementation Guide 2025-02-20

Details

Check Text (C-14744r296229_chk)
Examine the <JBOSS_HOME> folder. If a jboss-eap-6.3.0-GA-quickstarts folder exits, this is a finding.
Fix Text (F-14742r296230_fix)
Delete the QuickStarts folder.