STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server security auditing must be enabled.

DISA Rule

SV-255820r960765_rule

Vulnerability Number

V-255820

Group Title

SRG-APP-000016-AS-000013

Rule Version

WBSP-AS-000070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the administrative console, navigate to Security >> Security auditing to enable.

Restart the DMGR and all the JVMs.

Check Contents

In the administrative console, navigate to Security >> Security auditing.

If "Enable security auditing" is not enabled, this is a finding.

Vulnerability Number

V-255820

Documentable

False

Rule Version

WBSP-AS-000070

Severity Override Guidance

In the administrative console, navigate to Security >> Security auditing.

If "Enable security auditing" is not enabled, this is a finding.

Check Content Reference

M

Target Key

5510