STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

Custom database code and associated application code must reveal detailed error messages only to the Information System Security Officer (ISSO), Information System Security manager (ISSM), Systems Administrator (SA), and Database Administrator (DBA).

DISA Rule

SV-251627r961170_rule

Vulnerability Number

V-251627

Group Title

SRG-APP-000267-DB-000163

Rule Version

IDMS-DB-000560

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure custom database code and associated application code not to display detailed error messages to those not authorized to view them.

Check Contents

Check custom database code to determine if detailed error messages are ever displayed to unauthorized individuals.

If detailed error messages are displayed to individuals not authorized to view them, this is a finding.

Vulnerability Number

V-251627

Documentable

False

Rule Version

IDMS-DB-000560

Severity Override Guidance

Check custom database code to determine if detailed error messages are ever displayed to unauthorized individuals.

If detailed error messages are displayed to individuals not authorized to view them, this is a finding.

Check Content Reference

M

Target Key

5418