STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values.

DISA Rule

SV-220371r961119_rule

Vulnerability Number

V-220371

Group Title

SRG-APP-000224-DB-000384

Rule Version

ML09-00-004800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure MarkLogic settings to enable protections against man-in-the-middle attacks that guess at session identifier values.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
See: https://docs.marklogic.com/guide/security/SSL

1. Click the Groups icon.
2. Click the group in which the App Server to check resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. For each of the app servers that has a "no" under the SSL column, follow the instructions outlined in MarkLogic Server - Security Guide Rev 9-0.9, Chapter 9.0: Configuring SSL on App Servers.

Check Contents

Review MarkLogic settings to determine whether protections against man-in-the-middle attacks that guess at session identifier values are enabled.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to check resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. If any of the application servers has a "no" under the SSL column, this is a finding.

Vulnerability Number

V-220371

Documentable

False

Rule Version

ML09-00-004800

Severity Override Guidance

Review MarkLogic settings to determine whether protections against man-in-the-middle attacks that guess at session identifier values are enabled.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the App Server to check resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. If any of the application servers has a "no" under the SSL column, this is a finding.

Check Content Reference

M

Target Key

4064