STIGQter STIGQter: STIG Summary: IBM WebSphere Liberty Server Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Apr 2026:

The WebSphere Liberty Server must protect log information from unauthorized access or changes.

DISA Rule

SV-250328r960933_rule

Vulnerability Number

V-250328

Group Title

SRG-APP-000119-AS-000079

Rule Version

IBMW-LS-000260

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

As a user with local file access to ${server.config.dir}/logs, use the chmod command to configure the following log files to have the correct file permissions of 660.

chmod 660 <filename.log>

audit.log
messages.log
console.log
trace.log (if it exists)

Check Contents

As a user with local file access to ${server.config.dir}/logs, verify the following audit log files have the correct file permissions of 660.

audit.log
messages.log
console.log
trace.log (if it exists)

If the file permissions for these files are not set to 660, this is a finding.

Vulnerability Number

V-250328

Documentable

False

Rule Version

IBMW-LS-000260

Severity Override Guidance

As a user with local file access to ${server.config.dir}/logs, verify the following audit log files have the correct file permissions of 660.

audit.log
messages.log
console.log
trace.log (if it exists)

If the file permissions for these files are not set to 660, this is a finding.

Check Content Reference

M

Target Key

5424