STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must disable network functions, ports, protocols, and services deemed by the organization to be nonsecure, in accordance with Ports, Protocols, and Services Management (PPSM) guidance.

DISA Rule

SV-220384r961470_rule

Vulnerability Number

V-220384

Group Title

SRG-APP-000383-DB-000364

Rule Version

ML09-00-008000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable each prohibited network function, port, protocol, or service in MarkLogic.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the configuration to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. For any App Server that uses a prohibited port or protocol either disable the App Server or reconfigure to be compliant with the PPSM.

Check Contents

Review the network functions, ports, protocols, and services supported by MarkLogic for any that are prohibited by the PPSM guidance.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the configuration to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Inspect the Summary screen for the Type/Port/ and SSL configuration.
5. If any of the App Servers uses a protocol or port prohibited by the PPSM guidance, this is a finding.

Vulnerability Number

V-220384

Documentable

False

Rule Version

ML09-00-008000

Severity Override Guidance

Review the network functions, ports, protocols, and services supported by MarkLogic for any that are prohibited by the PPSM guidance.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the configuration to be checked resides (e.g., Default).
3. Click the App Servers icon on the left tree menu.
4. Inspect the Summary screen for the Type/Port/ and SSL configuration.
5. If any of the App Servers uses a protocol or port prohibited by the PPSM guidance, this is a finding.

Check Content Reference

M

Target Key

4064