STIGQter STIGQter: STIG Summary: zOS WebSphere Application Server for TSS Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

The CBIND Resource(s) for the WebSphere Application Server is(are) not protected in accordance with security requirements.

DISA Rule

SV-225620r1146190_rule

Vulnerability Number

V-225620

Group Title

SRG-OS-000080

Rule Version

ZWAS0030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the following items are in effect for CBIND resource protection:

The CB. resource is owned appropriately in the BIND resource class.

For Example:
TSS ADD(cbowner) CBIND(CB)

Access to the CB.BIND.server_name and CB.server_name resources is restricted to WAS server (STC) ACIDs and systems management ACIDs (e.g., WebSphere administrator ID).

For Example:
The WebSphere administrator ID needs READ access to the CB.BBOASR1 and CB.BIND.BBOASR1 servers:

TSS PERMIT(was_admin_acid) CBIND(CB.BBOASR1) ACCESS(READ)
TSS PERMIT(was_admin_acid) CBIND(CB.BIND.BBOASR1) ACCESS(READ)

Note: When adding a new server, all systems management userids (e.g., WebSphere administrator ID) must be authorized to have READ access to the CB.server_name and CB.BIND.server_name resources.

Check Contents

Refer to the following reports produced by the Data Set and Resource Data Collection:

- TSSCMDS.RPT(WHOOCBIN).
- TSSCMDS.RPT(WHOHCBIN).
- SENSITVE.RPT(WHOHCBIN).

If the following items are in effect for CBIND resource protection, this is not a finding.

The CB. resource is owned appropriately in the BIND resource class.

Access to the CB.BIND.server_name and CB.server_name resources is restricted to WAS server (STC) ACIDs and systems management ACIDs (e.g., WebSphere administrator ID).

Vulnerability Number

V-225620

Documentable

False

Rule Version

ZWAS0030

Severity Override Guidance

Refer to the following reports produced by the Data Set and Resource Data Collection:

- TSSCMDS.RPT(WHOOCBIN).
- TSSCMDS.RPT(WHOHCBIN).
- SENSITVE.RPT(WHOHCBIN).

If the following items are in effect for CBIND resource protection, this is not a finding.

The CB. resource is owned appropriately in the BIND resource class.

Access to the CB.BIND.server_name and CB.server_name resources is restricted to WAS server (STC) ACIDs and systems management ACIDs (e.g., WebSphere administrator ID).

Check Content Reference

M

Target Key

4210