STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

The DBMS must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.

DISA Rule

SV-251653r961167_rule

Vulnerability Number

V-251653

Group Title

SRG-APP-000266-DB-000162

Rule Version

IDMS-DB-000920

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop an IDMS user exit WTOEXIT to review, alter, redirect and suppress text of IDMS messages written to the operator's console. (Note that some system messages are written to the DC/UCF log as they are originally issued. Some system messages are written only to the console, regardless of how they are defined in the message dictionary).

Check Contents

Consult the system DBA and review system procedures for WTO exits that modify IDMS messages that go to non-privileged users.

If there is no procedure, this is a finding.

Vulnerability Number

V-251653

Documentable

False

Rule Version

IDMS-DB-000920

Severity Override Guidance

Consult the system DBA and review system procedures for WTO exits that modify IDMS messages that go to non-privileged users.

If there is no procedure, this is a finding.

Check Content Reference

M

Target Key

5418