STIGQter STIGQter: STIG Summary: Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2026:

TCMax must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).

DISA Rule

SV-281382r1186167_rule

Vulnerability Number

V-281382

Group Title

SRG-APP-000148

Rule Version

TCMA-09-000347

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options.

2. Under the Login and User Options, disable "Allow users to set item status without being logged in".

3. Click "Save".

Check Contents

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options >> General tab.

2. Under "Login and User Options", ensure "Allow users to set item status without being logged in" is unchecked.

If this option is enabled, this is a finding.

Vulnerability Number

V-281382

Documentable

False

Rule Version

TCMA-09-000347

Severity Override Guidance

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options >> General tab.

2. Under "Login and User Options", ensure "Allow users to set item status without being logged in" is unchecked.

If this option is enabled, this is a finding.

Check Content Reference

M

Target Key

5734