STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server must disable JSP class reloading.

DISA Rule

SV-255861r960963_rule

Vulnerability Number

V-255861

Group Title

SRG-APP-000141-AS-000095

Rule Version

WBSP-AS-000970

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To disable JSP reloading:

From the admin console, navigate to: Applications >> All applications >> [application name] >> JSP and JSP options.

Uncheck "JSP enable class reloading".

Check Contents

From admin console, navigate to: Applications >> All applications >> [application name] >> JSP and JSP options.

If "JSP enable class reloading" is checked, this is a finding.

Vulnerability Number

V-255861

Documentable

False

Rule Version

WBSP-AS-000970

Severity Override Guidance

From admin console, navigate to: Applications >> All applications >> [application name] >> JSP and JSP options.

If "JSP enable class reloading" is checked, this is a finding.

Check Content Reference

M

Target Key

5510