STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server Java 2 security must be enabled.

DISA Rule

SV-255833r1137578_rule

Vulnerability Number

V-255833

Group Title

SRG-APP-000033-AS-000024

Rule Version

WBSP-AS-000211

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the admin console, select Security >> Global Security >> Java 2 Security.

Select the "Use Java 2 security to restrict application access to local resources" check box.

Ensure the application security policies are defined and access permissions are granted accordingly.

Policies are created and access is granted on an application by application basis. Application access to the underlying host is based upon application access requirements.

Check Contents

From the admin console, select Security >> Global Security >> Java 2 Security.

If "Use Java 2 security to restrict application access to local resources" is not selected, this is a finding.

Vulnerability Number

V-255833

Documentable

False

Rule Version

WBSP-AS-000211

Severity Override Guidance

From the admin console, select Security >> Global Security >> Java 2 Security.

If "Use Java 2 security to restrict application access to local resources" is not selected, this is a finding.

Check Content Reference

M

Target Key

5510