SV-220374r961167_rule
V-220374
SRG-APP-000266-DB-000162
ML09-00-005900
CAT II
10
Configure MarkLogic log settings not to divulge sensitive information or information useful for system identification in error messages.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group that is to be fixed.
3. Set the "system log level" to "notice" and the "file log level" to "info".
Check MarkLogic settings and custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group that is to be checked.
3. Check settings for "file log level" and "system log level".
If "file log level" is set to "debug", "finer", or "finest", this is a finding.
If "system log level" is set to "debug", "finer", or "finest", this is a finding.
V-220374
False
ML09-00-005900
Check MarkLogic settings and custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group that is to be checked.
3. Check settings for "file log level" and "system log level".
If "file log level" is set to "debug", "finer", or "finest", this is a finding.
If "system log level" is set to "debug", "finer", or "finest", this is a finding.
M
4064