STIGQter STIGQter: STIG Summary: Application Server Security Requirements Guide Version: 3 Release: 1 Benchmark Date: 23 Oct 2020:

The application server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-204744r508029_rule

Vulnerability Number

V-204744

Group Title

SRG-APP-000142

Rule Version

SRG-APP-000142-AS-000014

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the application server to disable any ports or protocols that are prohibited by the PPSM CAL and vulnerability assessments.

Check Contents

Review the application server documentation and deployment configuration to determine which ports and protocols are enabled.

Verify that the ports and protocols being used are not prohibited and are necessary for the operation of the application server and the hosted applications.

If any of the ports or protocols is prohibited or not necessary for the application server operation, this is a finding.

Vulnerability Number

V-204744

Documentable

False

Rule Version

SRG-APP-000142-AS-000014

Severity Override Guidance

Review the application server documentation and deployment configuration to determine which ports and protocols are enabled.

Verify that the ports and protocols being used are not prohibited and are necessary for the operation of the application server and the hosted applications.

If any of the ports or protocols is prohibited or not necessary for the application server operation, this is a finding.

Check Content Reference

M

Target Key

2900

Comments