STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must separate user functionality (including user interface services) from database management functionality.

DISA Rule

SV-220370r961095_rule

Vulnerability Number

V-220370

Group Title

SRG-APP-000211-DB-000122

Rule Version

ML09-00-004500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure MarkLogic user roles so that only actual Administrators are assigned Administrative roles and each Administrator has an individual account.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users.
4. Remove administrative privileges from general user accounts, and ensure administrators have separate administrative accounts.

Check Contents

Validate MarkLogic User accounts to verify only Administrators have Administrative roles assigned and each Administrator has an individual account.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. If administrator and general user accounts are not separated, this is a finding.

Vulnerability Number

V-220370

Documentable

False

Rule Version

ML09-00-004500

Severity Override Guidance

Validate MarkLogic User accounts to verify only Administrators have Administrative roles assigned and each Administrator has an individual account.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. If administrator and general user accounts are not separated, this is a finding.

Check Content Reference

M

Target Key

4064