STIGQter STIGQter: STIG Summary: zOS Websphere Application Server for RACF Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

MVS data sets for the WebSphere Application Server are not protected in accordance with the proper security requirements.

DISA Rule

SV-224546r1145026_rule

Vulnerability Number

V-224546

Group Title

SRG-OS-000080

Rule Version

ZWAS0010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO will ensure that WebSphere server data sets restrict UPDATE and/or ALTER access to systems programming personnel.

Ensure the following data set controls are in effect for WAS:

WRITE and/or greater access to HTTP product data sets (i.e., SYS1.IMW.AIMW** and SYS1.IMW.SIMW**) are restricted to systems programming personnel.

Note: If the HTTP server is not used with WAS, this check can be ignored.

WRITE and/or greater access to WAS product data sets and associated product data sets are restricted to systems programming personnel.

SYS*.EJS.V3500108.** (WebSphere 3.5)
SYS*.WAS.V401.** (WebSphere 4.0.1)
SYS*.OE.** (Java)
SYS*.JAVA** (Java)
SYS*.DB2.V710107.** (DB2)
SYS*.GLD.** (LDAP)
SYS1.LE.** (Language Environment)

Check Contents

Refer to the following reports produced by the Data Set and Resource Data Collection:

- SENSITVE.RPT(HTTPRPT).
- SENSITVE.RPT(WASRPT).

If the following data set controls are in effect for WAS, this is not a finding.

The ACP data set rules restrict WRITE and/or greater access to HTTP product data sets (i.e., SYS1.IMW.AIMW** and SYS1.IMW.SIMW**) is restricted to systems programming personnel.

Note: If the HTTP server is not used with WAS, this check can be ignored.

The ACP data set rules restrict WRITE and/or greater access to WAS product data sets and associated product data sets are restricted to systems programming personnel.

SYS*.EJS.V3500108.** (WebSphere 3.5)
SYS*.WAS.V401.** (WebSphere 4.0.1)
SYS*.OE.** (Java)
SYS*.JAVA** (Java)
SYS*.DB2.V710107.** (DB2)
SYS*.GLD.** (LDAP)
SYS1.LE.** (Language Environment)

Vulnerability Number

V-224546

Documentable

False

Rule Version

ZWAS0010

Severity Override Guidance

Refer to the following reports produced by the Data Set and Resource Data Collection:

- SENSITVE.RPT(HTTPRPT).
- SENSITVE.RPT(WASRPT).

If the following data set controls are in effect for WAS, this is not a finding.

The ACP data set rules restrict WRITE and/or greater access to HTTP product data sets (i.e., SYS1.IMW.AIMW** and SYS1.IMW.SIMW**) is restricted to systems programming personnel.

Note: If the HTTP server is not used with WAS, this check can be ignored.

The ACP data set rules restrict WRITE and/or greater access to WAS product data sets and associated product data sets are restricted to systems programming personnel.

SYS*.EJS.V3500108.** (WebSphere 3.5)
SYS*.WAS.V401.** (WebSphere 4.0.1)
SYS*.OE.** (Java)
SYS*.JAVA** (Java)
SYS*.DB2.V710107.** (DB2)
SYS*.GLD.** (LDAP)
SYS1.LE.** (Language Environment)

Check Content Reference

M

Target Key

4166