Apache tomcat vulnerabilities

1) As a rough figure how often do Apach release security patches for Tomcat? I.e. per month, per week, how many?

2) And what tools can admins use to ensure that their apache is kept up to date? Do apache provide any free ones?

3) What would auditors look for when reviewing pacth management procedures for non MS software? For example if you did a scan and it said "apache out of date", they may apply a patch and then rescan and its gone, only for next week 5 more patches to come out and then its insecure again, and the process isnt managed.

4) So what demonstrates good patch management, i.e. what visually shows the auditor that this problem wont happen again?
LVL 4
pma111Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

pma111Author Commented:
And should a vulnerability assessment/pen test identify "how things came to be so insecure", or is the va/pen test really just to show "this is how insecure how things are, here are the quick fixes, the strategy behind how these are prevented long term is your audit depts problem not us"?
0
Leon FesterSenior Solutions ArchitectCommented:
Check the quick downloads section:
http://benchmarks.cisecurity.org/en-us/?route=default
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
pma111Author Commented:
Thanks for the benchmark, but I'd still appreciate replies in line with 1-5 posted above for future reference.
0
Leon FesterSenior Solutions ArchitectCommented:
Did you even bother to look at the link and download one of the files from this site?

If you did then you'd see a whole lot more than just a 1-5 point.

Here is a snippet of one of the items in the Benchmarks

1.3.3 Lock the Apache User Account (Level 1, Scorable)
:Description
The user account under which Apache runs, should not have a valid password, but should be locked.

Rationale:
As a defense-in-depth measure the Apache user account should be locked to prevent logins, and to prevent a user from su-ing to apache using the password. In general, there shouldn’t
21 | P a g e
be a need for anyone to su as apache. If a need does exist, sudo should be used instead, which would not require the apache account password.

Remediation:
Use the passwd command to lock the apache account: # passwd -l apache

Audit:
Ensure the apache account is locked using the following:
# passwd -s apache
The results will be similar to the following:
apache LK 2010-01-28 0 99999 7 -1 (Password locked.)

Default Value:
The default user is daemon and is locked.

So you've got information to do the following
Describe your problems/issues
Rationale behind the recommendation
Remediation Actions to fix the problem
How to audit
Default values

If you apply the benchmark remediation correctly then you probably won't have many failed audit issues.
0
pma111Author Commented:
I did indeed and many thanks, but it would be useful to see how many on average security updates for apache are released per month, and I could find this information.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Vulnerabilities

From novice to tech pro — start learning today.