STIGQter STIGQter: STIG Summary: zOS WebSphere Application Server for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

MVS datasets for the WebSphere Application Server are not protected in accordance with the proper security requirements.

DISA Rule

SV-224349r1141669_rule

Vulnerability Number

V-224349

Group Title

SRG-OS-000080

Rule Version

ZWAS0010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO will ensure that WebSphere server datasets restrict WRITE and/or greater access to systems programming personnel.

Ensure the following dataset controls are in effect for WAS:

WRITE and/or greater access to HTTP product datasets (i.e., SYS1.IMW.AIMW** and SYS1.IMW.SIMW**) are restricted to systems programming personnel.

Note: If the HTTP server is not used with WAS, this check can be ignored.

WRITE and/or greater access to WAS product datasets and associated product datasets are restricted to systems programming personnel.

SYS*.EJS.V3500108.** (WebSphere 3.5)
SYS*.WAS.V401.** (WebSphere 4.0.1)
SYS*.OE.** (Java)
SYS*.JAVA** (Java)
SYS*.DB2.V710107.** (DB2)
SYS*.GLD.** (LDAP)
SYS1.LE.** (Language Environment)

Check Contents

Refer to the following reports produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(HTTPRPT).
- SENSITVE.RPT(WASRPT).

If the following dataset controls are in effect for WAS, this is not a finding.

The ACP dataset rules restrict WRITE and/or greater access to HTTP product datasets (i.e., SYS1.IMW.AIMW** and SYS1.IMW.SIMW**) is restricted to systems programming personnel.

Note: If the HTTP server is not used with WAS, this check can be ignored.

The ACP dataset rules restrict WRITE and/or greater access to WAS product datasets and associated product datasets are restricted to systems programming personnel.

SYS*.EJS.V3500108.** (WebSphere 3.5)
SYS*.WAS.V401.** (WebSphere 4.0.1)
SYS*.OE.** (Java)
SYS*.JAVA** (Java)
SYS*.DB2.V710107.** (DB2)
SYS*.GLD.** (LDAP)
SYS1.LE.** (Language Environment)

Vulnerability Number

V-224349

Documentable

False

Rule Version

ZWAS0010

Severity Override Guidance

Refer to the following reports produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(HTTPRPT).
- SENSITVE.RPT(WASRPT).

If the following dataset controls are in effect for WAS, this is not a finding.

The ACP dataset rules restrict WRITE and/or greater access to HTTP product datasets (i.e., SYS1.IMW.AIMW** and SYS1.IMW.SIMW**) is restricted to systems programming personnel.

Note: If the HTTP server is not used with WAS, this check can be ignored.

The ACP dataset rules restrict WRITE and/or greater access to WAS product datasets and associated product datasets are restricted to systems programming personnel.

SYS*.EJS.V3500108.** (WebSphere 3.5)
SYS*.WAS.V401.** (WebSphere 4.0.1)
SYS*.OE.** (Java)
SYS*.JAVA** (Java)
SYS*.DB2.V710107.** (DB2)
SYS*.GLD.** (LDAP)
SYS1.LE.** (Language Environment)

Check Content Reference

M

Target Key

4132