STIGQter STIGQter: STIG Summary: MariaDB Enterprise 10.x Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Apr 2026:

If passwords are used for authentication, MariaDB must store only hashed, salted representations of passwords.

DISA Rule

SV-253697r1018600_rule

Vulnerability Number

V-253697

Group Title

SRG-APP-000171-DB-000074

Rule Version

MADB-10-003800

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Document all applications, scripts, etc., which connect to the database server. Ensure passwords, if stored, are encrypted and secure.

Check Contents

MariaDB stores passwords encrypted. When querying users, the passwords are displayed encrypted.

However, third-party applications, scripts, etc., might be storing passwords. In such cases, it is important to ensure these passwords are encrypted. Check all third-party applications, scripts, etc., which connect to the database and verify the passwords are encrypted. If any passwords are found in clear text, this is a finding.

Vulnerability Number

V-253697

Documentable

False

Rule Version

MADB-10-003800

Severity Override Guidance

MariaDB stores passwords encrypted. When querying users, the passwords are displayed encrypted.

However, third-party applications, scripts, etc., might be storing passwords. In such cases, it is important to ensure these passwords are encrypted. Check all third-party applications, scripts, etc., which connect to the database and verify the passwords are encrypted. If any passwords are found in clear text, this is a finding.

Check Content Reference

M

Target Key

5475