STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.

DISA Rule

SV-220374r961167_rule

Vulnerability Number

V-220374

Group Title

SRG-APP-000266-DB-000162

Rule Version

ML09-00-005900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure MarkLogic log settings not to divulge sensitive information or information useful for system identification in error messages.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group that is to be fixed.
3. Set the "system log level" to "notice" and the "file log level" to "info".

Check Contents

Check MarkLogic settings and custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group that is to be checked.
3. Check settings for "file log level" and "system log level".

If "file log level" is set to "debug", "finer", or "finest", this is a finding.

If "system log level" is set to "debug", "finer", or "finest", this is a finding.

Vulnerability Number

V-220374

Documentable

False

Rule Version

ML09-00-005900

Severity Override Guidance

Check MarkLogic settings and custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group that is to be checked.
3. Check settings for "file log level" and "system log level".

If "file log level" is set to "debug", "finer", or "finest", this is a finding.

If "system log level" is set to "debug", "finer", or "finest", this is a finding.

Check Content Reference

M

Target Key

4064