STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

IDMS must protect against the use of numbered exits that change the userid to a shared id.

DISA Rule

SV-251596r960864_rule

Vulnerability Number

V-251596

Group Title

SRG-APP-000080-DB-000063

Rule Version

IDMS-DB-000160

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Remove code from exit 27 and/or exit 28 that changes the individual user id to a shared user or remove the exit entirely, then reassemble and relink RHDCUXIT.

To implement the new RHDCUXIT, either recycle any CVs that use the SRTT or issue these commands:

DCMT VARY NUCLEUS MODULE RHDCUXIT NEW COPY
DCMT VARY NUCLEUS RELOAD

Check Contents

Issue LOOK PROGRAM=RHDCUXIT. If there are non-zeros in the 12 bytes starting at X'200', exit 27 is being used.

If there are non-zeros in the 12 bytes starting at X'20C', exit 28 is being used.

Check exits for a change in userid and if there is a change to a shared user ID, this is a finding.

Vulnerability Number

V-251596

Documentable

False

Rule Version

IDMS-DB-000160

Severity Override Guidance

Issue LOOK PROGRAM=RHDCUXIT. If there are non-zeros in the 12 bytes starting at X'200', exit 27 is being used.

If there are non-zeros in the 12 bytes starting at X'20C', exit 28 is being used.

Check exits for a change in userid and if there is a change to a shared user ID, this is a finding.

Check Content Reference

M

Target Key

5418