STIGQter STIGQter: STIG Summary: zOS Websphere Application Server for RACF Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

HFS objects for the WebSphere Application Server are not protected in accordance with the proper security requirements.

DISA Rule

SV-224547r1145029_rule

Vulnerability Number

V-224547

Group Title

SRG-OS-000080

Rule Version

ZWAS0020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review the UNIX permission bits, user audit bits, and ownership settings on the HFS directories and files for the products required to support the WAS environment.

Ensure the HFS permission bits, user audit bits, owner, and group for each directory and file match the specified settings listed in the HFS Permissions Bits table located in the zOS STIG Addendum.

Check Contents

Refer to the following reports produced by the z/OS Data Collection:

- USSCMDS.RPT(IHSHFSOB).
- USSCMDS.RPT(WASHFSOB).

For each IBM HTTP server, supply the following information: (PDS member name - IHSACCTS)

- Web server ID defined to the ACP.
- Web server administration group defined to the ACP.
- Web server standard HFS directory.

The following notes apply to the requirements specified in the HFS Permission Bits table in the z/OS STIG Addendum. If the following guidance is true, this is not a finding.

- If an owner field indicates UID(0) user, any system ID with a UID(0) specification is acceptable.
- Where an owner field indicates websrv1, the ID of the web server is intended.
- Where a group field indicates webadmg1, the ID of a local web server administration group is intended. IMWEB is not a valid local group.
- The site is free to set the permission and audit bit settings to be more restrictive than the documented values.

The following represents a hierarchy for permission bits from least restrictive to most restrictive:

7 rwx (least restrictive)
6 rw-
3 -wx
2 -w-
5 r-x
4 r--
1 --x
0 --- (most restrictive)

The possible audit bits settings are as follows:

f log for failed access attempts
a log for failed and successful access
- no auditing

Vulnerability Number

V-224547

Documentable

False

Rule Version

ZWAS0020

Severity Override Guidance

Refer to the following reports produced by the z/OS Data Collection:

- USSCMDS.RPT(IHSHFSOB).
- USSCMDS.RPT(WASHFSOB).

For each IBM HTTP server, supply the following information: (PDS member name - IHSACCTS)

- Web server ID defined to the ACP.
- Web server administration group defined to the ACP.
- Web server standard HFS directory.

The following notes apply to the requirements specified in the HFS Permission Bits table in the z/OS STIG Addendum. If the following guidance is true, this is not a finding.

- If an owner field indicates UID(0) user, any system ID with a UID(0) specification is acceptable.
- Where an owner field indicates websrv1, the ID of the web server is intended.
- Where a group field indicates webadmg1, the ID of a local web server administration group is intended. IMWEB is not a valid local group.
- The site is free to set the permission and audit bit settings to be more restrictive than the documented values.

The following represents a hierarchy for permission bits from least restrictive to most restrictive:

7 rwx (least restrictive)
6 rw-
3 -wx
2 -w-
5 r-x
4 r--
1 --x
0 --- (most restrictive)

The possible audit bits settings are as follows:

f log for failed access attempts
a log for failed and successful access
- no auditing

Check Content Reference

M

Target Key

4166