STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

Access to API privileged features and functions must be restricted.

DISA Rule

SV-274643r1143676_rule

Vulnerability Number

V-274643

Group Title

SRG-APP-000340

Rule Version

SRG-APP-000340-API-000675

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to Implement and enforce access controls that restrict privileged API features and functions (administrative actions, configuration changes, data modification, and sensitive data access) to authorized users only.

Check Contents

Review access controls for API privileged features and functions (administrative operations, configuration management, data modification, and access to sensitive information).

If unauthorized users can access any of these privileged capabilities, this is a finding.

Vulnerability Number

V-274643

Documentable

False

Rule Version

SRG-APP-000340-API-000675

Severity Override Guidance

Review access controls for API privileged features and functions (administrative operations, configuration management, data modification, and access to sensitive information).

If unauthorized users can access any of these privileged capabilities, this is a finding.

Check Content Reference

M

Target Key

5703