STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server users in the WebSphere auditor role must be configured in accordance with the System Security Plan.

DISA Rule

SV-255822r960765_rule

Vulnerability Number

V-255822

Group Title

SRG-APP-000016-AS-000013

Rule Version

WBSP-AS-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the administrative console, navigate to Users and Groups >> Administrative User roles.

If an unauthorized user is in the auditor role, remove the user from the auditor role.

Restart the DMGR and all the JVMs.

Check Contents

Review System Security Plan documentation.

Identify users and roles.

In the administrative console, navigate to Users and Groups >> Administrative User Roles.

Check the roles for each user.

If any user is not authorized by the ISSO/ISSM to be in the role of an auditor, this is a finding.

Vulnerability Number

V-255822

Documentable

False

Rule Version

WBSP-AS-000090

Severity Override Guidance

Review System Security Plan documentation.

Identify users and roles.

In the administrative console, navigate to Users and Groups >> Administrative User Roles.

Check the roles for each user.

If any user is not authorized by the ISSO/ISSM to be in the role of an auditor, this is a finding.

Check Content Reference

M

Target Key

5510