How to Secure Apache Tomcat 8 in 15 Steps | UpGuard
ID: bd3fbeaf-a4b8-5fd1-a2e5-6ae7e2e51615
STIX ID: report--bd3fbeaf-a4b8-5fd1-a2e5-6ae7e2e51615
Feed Name: UpGuard Blog
This document outlines 15 practical steps to harden Apache Tomcat 8 out of the box, including running Tomcat as a non-root user, removing sample apps, locking down the shutdown port, disabling TRACE and the X-Powered-By header, disabling SSLv3 to prevent POODLE, restricting deployXML and automated deployment, choosing safer realms, recycling facades per request, enforcing read-only resources, disabling directory listings, enabling access logging, limiting or disabling the Manager app, and binding connectors to required interfaces, with references to OWASP and Tomcat security guides.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
