STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 28 Oct 2025:

To protect against unauthorized data mining, the IPS must prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.

DISA Rule

SV-206895r1137746_rule

Vulnerability Number

V-206895

Group Title

SRG-NET-000318

Rule Version

SRG-NET-000318-IDPS-00068

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IPS components to prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.

Check Contents

If the device being reviewed is an IDS, this is not applicable.

Verify the IPS prevents code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.

If the IPS does not prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields, this is a finding.

Vulnerability Number

V-206895

Documentable

False

Rule Version

SRG-NET-000318-IDPS-00068

Severity Override Guidance

If the device being reviewed is an IDS, this is not applicable.

Verify the IPS prevents code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.

If the IPS does not prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields, this is a finding.

Check Content Reference

M

Target Key

2918