The WebSphere Application Server security auditing must be enabled.
DISA Rule
SV-255820r960765_rule
Vulnerability Number
V-255820
Group Title
SRG-APP-000016-AS-000013
Rule Version
WBSP-AS-000070
Severity
CAT II
CCI(s)
- CCI-000067 - Employ automated mechanisms to monitor remote access methods.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-001312 - Generates error messages that provide information necessary for corrective actions without revealing information that could be exploited.
- CCI-001314 - Reveal error messages only to organization-defined personnel or roles.
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-002234 - Log the execution of privileged functions.
Weight
10
Fix Recommendation
In the administrative console, navigate to Security >> Security auditing to enable.
Restart the DMGR and all the JVMs.
Check Contents
In the administrative console, navigate to Security >> Security auditing.
If "Enable security auditing" is not enabled, this is a finding.
Vulnerability Number
V-255820
Documentable
False
Rule Version
WBSP-AS-000070
Severity Override Guidance
In the administrative console, navigate to Security >> Security auditing.
If "Enable security auditing" is not enabled, this is a finding.
Check Content Reference
M
Target Key
5510