STIGQter STIGQter: STIG Summary: IBM WebSphere Liberty Server Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Apr 2026:

The server.xml file must be protected from unauthorized modification.

DISA Rule

SV-250344r961461_rule

Vulnerability Number

V-250344

Group Title

SRG-APP-000380-AS-000088

Rule Version

IBMW-LS-000910

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

As a privileged user with local file access to ${server.config.dir}/server.xml.

Use the chmod command to configure the correct file permissions of 660.

chmod 660 server.xml

Check Contents

As a privileged user with local file access to ${server.config.dir}/server.xml, verify the server.xml file permissions are set to 660.

If the server.xml file permissions are not set to 660, this is a finding.

Vulnerability Number

V-250344

Documentable

False

Rule Version

IBMW-LS-000910

Severity Override Guidance

As a privileged user with local file access to ${server.config.dir}/server.xml, verify the server.xml file permissions are set to 660.

If the server.xml file permissions are not set to 660, this is a finding.

Check Content Reference

M

Target Key

5424