STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 28 Oct 2025:

To protect against unauthorized data mining, the IPS must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.

DISA Rule

SV-206897r1137752_rule

Vulnerability Number

V-206897

Group Title

SRG-NET-000318

Rule Version

SRG-NET-000318-IDPS-00183

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IPS to prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.

Check Contents

If the device being reviewed is an IDS, this is not applicable.

Verify the IPS prevents SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.

If the IPS does not prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields, this is a finding.

Vulnerability Number

V-206897

Documentable

False

Rule Version

SRG-NET-000318-IDPS-00183

Severity Override Guidance

If the device being reviewed is an IDS, this is not applicable.

Verify the IPS prevents SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.

If the IPS does not prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields, this is a finding.

Check Content Reference

M

Target Key

2918