STIGQter STIGQter: STIG Summary: SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

SLEM 5 must use the invoking user's password for privilege escalation when using "sudo".

DISA Rule

SV-261372r1184420_rule

Vulnerability Number

V-261372

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

SLEM-05-432010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the sudoers security policy to use the invoking user's password for privilege escalation.

Define the defaults in a configuration file in the /etc/sudoers.d/ directory with the following command and entries:

> sudo visudo -f /etc/sudoers.d/hardening_defaults

Defaults !targetpw
Defaults !rootpw
Defaults !runaspw

Check Contents

Verify that the sudoers security policy is configured to use the invoking user's password for privilege escalation with the following command:

> sudo egrep -ir '(rootpw|targetpw|runaspw)' /etc/sudoers /etc/sudoers.d* | grep -v '#'
/etc/sudoers.d/hardening_defaults:Defaults !targetpw
/etc/sudoers.d/hardening_defaults:Defaults !rootpw
/etc/sudoers.d/hardening_defaults:Defaults !runaspw

If "Defaults" types are not defined for "!targetpw", "!rootpw", and "!runaspw", there are conflicting results between files, this is a finding.

Vulnerability Number

V-261372

Documentable

False

Rule Version

SLEM-05-432010

Severity Override Guidance

Verify that the sudoers security policy is configured to use the invoking user's password for privilege escalation with the following command:

> sudo egrep -ir '(rootpw|targetpw|runaspw)' /etc/sudoers /etc/sudoers.d* | grep -v '#'
/etc/sudoers.d/hardening_defaults:Defaults !targetpw
/etc/sudoers.d/hardening_defaults:Defaults !rootpw
/etc/sudoers.d/hardening_defaults:Defaults !runaspw

If "Defaults" types are not defined for "!targetpw", "!rootpw", and "!runaspw", there are conflicting results between files, this is a finding.

Check Content Reference

M

Target Key

5596