STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

Custom database code and associated application code must not contain information beyond what is needed for troubleshooting.

DISA Rule

SV-251625r961167_rule

Vulnerability Number

V-251625

Group Title

SRG-APP-000266-DB-000162

Rule Version

IDMS-DB-000540

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure custom database code, and associated application code not to divulge sensitive information or information useful for system identification in error messages.

Check Contents

Check custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.

If database errors contain PII data, sensitive business data, or information useful for identifying the host system or database structure, this is a finding.

Vulnerability Number

V-251625

Documentable

False

Rule Version

IDMS-DB-000540

Severity Override Guidance

Check custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.

If database errors contain PII data, sensitive business data, or information useful for identifying the host system or database structure, this is a finding.

Check Content Reference

M

Target Key

5418