STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must be a version supported by the vendor.

DISA Rule

SV-265874r999528_rule

Vulnerability Number

V-265874

Group Title

SRG-APP-000456-DB-000400

Rule Version

ML09-00-012500

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Remove or decommission all unsupported software products.

Upgrade unsupported DBMS or unsupported components to a supported version of the product.

Check Contents

Review the system documentation and interview the database administrator.

Identify all database software components.

Review the current version and release information; execute the following from the query console:
xdmp:version();
--OR--
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
Version is displayed in the upper left corner of the console.

Access the MarkLogic website to validate that the version is currently supported:
https://developer.marklogic.com/products/support-matrix/

If the DBMS or any of the software components are not supported by the vendor, this is a finding.

Vulnerability Number

V-265874

Documentable

False

Rule Version

ML09-00-012500

Severity Override Guidance

Review the system documentation and interview the database administrator.

Identify all database software components.

Review the current version and release information; execute the following from the query console:
xdmp:version();
--OR--
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
Version is displayed in the upper left corner of the console.

Access the MarkLogic website to validate that the version is currently supported:
https://developer.marklogic.com/products/support-matrix/

If the DBMS or any of the software components are not supported by the vendor, this is a finding.

Check Content Reference

M

Target Key

4064