STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server bus security must be enabled.

DISA Rule

SV-255827r961863_rule

Vulnerability Number

V-255827

Group Title

SRG-APP-000516-AS-000237

Rule Version

WBSP-AS-000140

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the administration console, navigate to Security >> Bus Security.

For each service integration bus where security is not enabled, click on "Disabled".

Click the check box to "Enable bus security".

Configure the transport settings and authorization policies according to application security access requirements specified in the security plan.

Check Contents

Review System Security Plan documentation.

Interview the system administrator.

Identify the service integration buses configured on the WAS.

If there are no service integration buses, this requirement is NA.

From the administration console, navigate to Security >> Bus Security.

For each service integration bus, if security is not enabled, this is a finding.

Vulnerability Number

V-255827

Documentable

False

Rule Version

WBSP-AS-000140

Severity Override Guidance

Review System Security Plan documentation.

Interview the system administrator.

Identify the service integration buses configured on the WAS.

If there are no service integration buses, this requirement is NA.

From the administration console, navigate to Security >> Bus Security.

For each service integration bus, if security is not enabled, this is a finding.

Check Content Reference

M

Target Key

5510