STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-220362r960966_rule

Vulnerability Number

V-220362

Group Title

SRG-APP-000142-DB-000094

Rule Version

ML09-00-003400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable functions, ports, protocols, and services that are not approved.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to check resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Inspect the list of App Servers and associated Protocols and Ports.
5. If any App Server has an associated protocol or port that is not approved, remove the App Server by selecting the server and selecting either "Disable" or "Delete".

Check Contents

Review the DBMS settings and local documentation for functions, ports, protocols, and services that are approved.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to check resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Inspect the list of App Servers and associated Protocols and Ports.
5. If any App Server has an associated protocol or port that is not approved, this is a finding.

Vulnerability Number

V-220362

Documentable

False

Rule Version

ML09-00-003400

Severity Override Guidance

Review the DBMS settings and local documentation for functions, ports, protocols, and services that are approved.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to check resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Inspect the list of App Servers and associated Protocols and Ports.
5. If any App Server has an associated protocol or port that is not approved, this is a finding.

Check Content Reference

M

Target Key

4064