STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server Single Sign On (SSO) must have SSL enabled for Web and SIP Security.

DISA Rule

SV-255831r960759_rule

Vulnerability Number

V-255831

Group Title

SRG-APP-000014-AS-000009

Rule Version

WBSP-AS-000180

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the administrative console, navigate to Security >> Global Security.

Expand "Web and SIP security".

Click on "Single sign-on (SSO)".

Select "Requires SSL".

Click "OK".

Click "Save".

Restart the DMGR and all the JVMs.

Check Contents

From the administrative console, navigate to Security >> Global Security.

Expand "Web and SIP security".

Click on "Single sign-on (SSO)".

If "requires SSL" is not selected, this is a finding.

Vulnerability Number

V-255831

Documentable

False

Rule Version

WBSP-AS-000180

Severity Override Guidance

From the administrative console, navigate to Security >> Global Security.

Expand "Web and SIP security".

Click on "Single sign-on (SSO)".

If "requires SSL" is not selected, this is a finding.

Check Content Reference

M

Target Key

5510