STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

Passwords sent through ODBC/JDBC must be encrypted.

DISA Rule

SV-251614r961029_rule

Vulnerability Number

V-251614

Group Title

SRG-APP-000172-DB-000075

Rule Version

IDMS-DB-000340

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

If using ODBC (with the CCI communications protocol) or a JDBC type 2 driver, SSL encryption can be enabled using CAICCI r2.1 and above. Select the SSL option in the CAICCI properties panel and configure and start the CCISSL task on the mainframe.

If using ODBC (with the IDMS communications protocol), SSL encryption can be enabled by selecting the "SSL" check-box on the "Server" tab of the Data Source definition, and providing the certificate name(s) on the "SSL" tab within the CA IDMS ODBC Administrator.

If using a JDBC type 4 driver, SSL encryption can be enabled by using the SSL parameter on the JDBC connection URL. Setup is described in informational APAR QI83006 on CA Support Online.

Check Contents

When using ODBC (with the CCI communications protocol) or a JDBC type 2 driver, if SSL encryption is not being used with CAICCI r2.1 and above, this is a finding.

When using ODBC (with the IDMS communications protocol), if SSL encryption is not being used as indicated on the "Server" tab of the Data Source definition, this is a finding.

When using a JDBC type 4 driver, if SSL is not being used as indicated by the connection URL, this is a finding.

Vulnerability Number

V-251614

Documentable

False

Rule Version

IDMS-DB-000340

Severity Override Guidance

When using ODBC (with the CCI communications protocol) or a JDBC type 2 driver, if SSL encryption is not being used with CAICCI r2.1 and above, this is a finding.

When using ODBC (with the IDMS communications protocol), if SSL encryption is not being used as indicated on the "Server" tab of the Data Source definition, this is a finding.

When using a JDBC type 4 driver, if SSL is not being used as indicated by the connection URL, this is a finding.

Check Content Reference

M

Target Key

5418