STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

IDMS must protect against the use of external request exits that change the userid to a shared id when actions are performed that may be audited.

DISA Rule

SV-251595r960864_rule

Vulnerability Number

V-251595

Group Title

SRG-APP-000080-DB-000063

Rule Version

IDMS-DB-000150

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Remove code from USRIDXIT that changes the individual userid to a shared user or remove the exit entirely.

After making the above changes, assemble and link IDMSUXIT. To implement the new IDMSUXIT either recycle any CVs that use it or issue these commands:

DCMT VARY NUCLEUS MODULE IDMSUXIT NEW COPY
DCMT VARY NUCLEUS RELOAD

Check Contents

Log in to the CV and enter command DCPROFIL. Press "Enter" until the page titled "Named User Exits" appears. Find the entry for USRIDXIT.

If the DEFINED column says YES, then a user-written exit has been linked with IDMSUXIT.

If a user-written exit USRIDXIT has been linked with IDMSUXIT (for batch or TSO-front end use), UCFCICS (UCF access from a CICS transaction) or IDMSINTC (DML or SQL access form a CICS transaction server front-end) and the USRIDXIT changes the userid to a shared userid, this is a finding.

Vulnerability Number

V-251595

Documentable

False

Rule Version

IDMS-DB-000150

Severity Override Guidance

Log in to the CV and enter command DCPROFIL. Press "Enter" until the page titled "Named User Exits" appears. Find the entry for USRIDXIT.

If the DEFINED column says YES, then a user-written exit has been linked with IDMSUXIT.

If a user-written exit USRIDXIT has been linked with IDMSUXIT (for batch or TSO-front end use), UCFCICS (UCF access from a CICS transaction) or IDMSINTC (DML or SQL access form a CICS transaction server front-end) and the USRIDXIT changes the userid to a shared userid, this is a finding.

Check Content Reference

M

Target Key

5418