STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).

DISA Rule

SV-220369r961053_rule

Vulnerability Number

V-220369

Group Title

SRG-APP-000180-DB-000115

Rule Version

ML09-00-004400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If non-organizational users are not uniquely identified and authenticated, implement the steps below.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users, and remove any non-organizational users who are not uniquely identified.

Check Contents

Review MarkLogic settings to determine if non-organizational users are uniquely identified and authenticated.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users; if there is a non-organizational user who is not uniquely identified, this is a finding.

Vulnerability Number

V-220369

Documentable

False

Rule Version

ML09-00-004400

Severity Override Guidance

Review MarkLogic settings to determine if non-organizational users are uniquely identified and authenticated.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users; if there is a non-organizational user who is not uniquely identified, this is a finding.

Check Content Reference

M

Target Key

4064