STIGQter STIGQter: STIG Summary: Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2026:

TCMax must be configured to prohibit or restrict using organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.

DISA Rule

SV-281369r1195319_rule

Vulnerability Number

V-281369

Group Title

SRG-APP-000142

Rule Version

TCMA-09-000051

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the connection to use ports approved by the PPSM CAL.

Check Contents

1. Using a Windows account of appropriate privileges to access the file system, open the file C:\ProgramData\Soaring Software Solutions\TCMax\Configuration Files\DatabaseConnections.xml.

2. Review the connection string attribute for Data Source.

If the port specified in the Data Source is not approved by the PPSM CAL, this is a finding.

Vulnerability Number

V-281369

Documentable

False

Rule Version

TCMA-09-000051

Severity Override Guidance

1. Using a Windows account of appropriate privileges to access the file system, open the file C:\ProgramData\Soaring Software Solutions\TCMax\Configuration Files\DatabaseConnections.xml.

2. Review the connection string attribute for Data Source.

If the port specified in the Data Source is not approved by the PPSM CAL, this is a finding.

Check Content Reference

M

Target Key

5734