STIGQter STIGQter: STIG Summary: Solaris 11 SPARC Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

The operating system must prevent the execution of prohibited mobile code.

DISA Rule

SV-216464r603267_rule

Vulnerability Number

V-216464

Group Title

SRG-OS-000181

Rule Version

SOL-11.1-090100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the address bar type: about:config

Click on "I accept the risk" button.

In search bar type: javascript.enabled

Double click on the javascript.enabled and Value true will change to false.

In the address bar type: about:addons

Click on "Plugins".

If Java is displayed, disable Java by clicking on the
Never Activate selection

Check Contents

Determine if the Firefox package is installed:

# pkg list web/browser/firefox

If the package is not installed, this check does not apply.

If installed, ensure that it is a supported version.

# pkg info firefox | grep Version
Version: 52.5.2

If the version is not supported, this is a finding.

Ensure that Java and JavaScript access by Firefox are disabled.

Start Firefox.

In the address bar type: about:config

In search bar type: javascript.enabled

If 'Value" is true, this is a finding

In the address bar type: about:addons

Click on "I accept the risk" button.

Click on "Plugins".

If Java is enabled, this is a finding.

Vulnerability Number

V-216464

Documentable

False

Rule Version

SOL-11.1-090100

Severity Override Guidance

Determine if the Firefox package is installed:

# pkg list web/browser/firefox

If the package is not installed, this check does not apply.

If installed, ensure that it is a supported version.

# pkg info firefox | grep Version
Version: 52.5.2

If the version is not supported, this is a finding.

Ensure that Java and JavaScript access by Firefox are disabled.

Start Firefox.

In the address bar type: about:config

In search bar type: javascript.enabled

If 'Value" is true, this is a finding

In the address bar type: about:addons

Click on "I accept the risk" button.

Click on "Plugins".

If Java is enabled, this is a finding.

Check Content Reference

M

Target Key

4022

Comments