STIGQter: STIG Summary: Apache Server 2.4 Windows Server Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2020: The Apache web server must generate unique session identifiers that cannot be reliably reproduced.DISA Rule
SV-102501r1_rule
Vulnerability Number
V-92413
Group Title
SRG-APP-000224-WSR-000136
Rule Version
AS24-W1-000500
Severity
CAT II
CCI(s)
- CCI-001188 - The information system generates unique session identifiers for each session with organization-defined randomness requirements.
Weight
10
Fix Recommendation
Edit the <'INSTALL PATH'>\conf\httpd.conf file and load the "mod_unique_id" module.
Restart the Apache service.
Check Contents
Review the <'INSTALL PATH'>\conf\httpd.conf file.
Check to see if the "mod_unique_id" is loaded.
If it does not exist, this is a finding.
Vulnerability Number
V-92413
Documentable
False
Rule Version
AS24-W1-000500
Severity Override Guidance
Review the <'INSTALL PATH'>\conf\httpd.conf file.
Check to see if the "mod_unique_id" is loaded.
If it does not exist, this is a finding.
Check Content Reference
M
Target Key
3415
Comments