STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.

DISA Rule

SV-220339r960735_rule

Vulnerability Number

V-220339

Group Title

SRG-APP-000001-DB-000031

Rule Version

ML09-00-000100

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Determine whether the system documentation specifies limits on the number of concurrent DBMS sessions per account by type of user. If it does not, assume a limit of 10 for database administrators and 2 for all other users.

Fix the concurrent-sessions settings in MarkLogic.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to be fixed resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select the App Server in which in which to fix session limits. The App Server Configuration page displays.
5. In the concurrent request limit field, enter a value corresponding to the organization-defined maximum number of concurrent user sessions to allow.
6. Repeat for all App Servers.

Check Contents

Determine whether the system documentation specifies limits on the number of concurrent DBMS sessions per account by type of user. If it does not, assume a limit of 10 for database administrators and 2 for all other users.

Check the concurrent-sessions settings in the MarkLogic.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select the App Server in which in which to check session limits. The App Server Configuration page displays.
5. Inspect the concurrent request limit field; a value of 0 means there is no concurrent request limit (unlimited), and this is a finding.
6. If a value other than 0 but not equal to the organization-defined number is set, this is a finding.
7. Repeat for all App Servers.

Vulnerability Number

V-220339

Documentable

False

Rule Version

ML09-00-000100

Severity Override Guidance

Determine whether the system documentation specifies limits on the number of concurrent DBMS sessions per account by type of user. If it does not, assume a limit of 10 for database administrators and 2 for all other users.

Check the concurrent-sessions settings in the MarkLogic.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Select the App Server in which in which to check session limits. The App Server Configuration page displays.
5. Inspect the concurrent request limit field; a value of 0 means there is no concurrent request limit (unlimited), and this is a finding.
6. If a value other than 0 but not equal to the organization-defined number is set, this is a finding.
7. Repeat for all App Servers.

Check Content Reference

M

Target Key

4064