The IBM z/OS UNIX Telnet server warning banner must be properly specified.
DISA Rule
SV-224103r958586_rule
Vulnerability Number
V-224103
Group Title
SRG-OS-000228-GPOS-00088
Rule Version
TSS0-UT-000050
Severity
CAT II
CCI(s)
- CCI-001384 - For publicly accessible systems, display system use information with organization-defined conditions before granting further access to the publicly accessible system.
- CCI-001385 - For publicly accessible systems, displays references, if any, to monitoring that are consistent with privacy accommodations for such systems that generally prohibit those activities.
- CCI-001386 - For publicly accessible systems, displays references, if any, to recording that are consistent with privacy accommodations for such systems that generally prohibit those activities.
- CCI-001387 - For publicly accessible systems, displays references, if any, to auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities.
- CCI-001388 - For publicly accessible systems, includes a description of the authorized uses of the system.
Weight
10
Fix Recommendation
The otelnetd startup command should not include the option "-h", where:
-h indicates that the logon banner should not be displayed.
Check Contents
From the ISPF Command Shell enter:
OMVS
cat inetd.conf
If the otelnet startup command includes option "-h" this is a finding.
Vulnerability Number
V-224103
Documentable
False
Rule Version
TSS0-UT-000050
Severity Override Guidance
From the ISPF Command Shell enter:
OMVS
cat inetd.conf
If the otelnet startup command includes option "-h" this is a finding.
Check Content Reference
M
Target Key
4102