STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 01 Apr 2026:

The WebSphere Application Server must use FIPS 140-3-approved encryption modules when authenticating users and processes.

DISA Rule

SV-283677r1193276_rule

Vulnerability Number

V-283677

Group Title

SRG-APP-000179-AS-000129

Rule Version

WBSP-AS-001770

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implementation for Cell Profile (Network Deployment):

1. Back up the existing configuration:

backupConfig.sh <backup_directory>

2. Stop all servers except the deployment manager:

- Stop all node agents and application servers.
- Keep only the deployment manager running.

3. Enable FIPS 140-3.

Option A - Using Administrative Console:
1. Click Security >> SSL certificate and key management >> Manage FIPS.


2. Select "Enable FIPS 140-3".
3. Click "Apply".

Option B - Using Admin Command:
AdminTask.enableFips('[-enableFips true -fipsLevel FIPS140-3 ]')

1. Stop the deployment manager.

2. Restart the deployment manager.

3. Synchronize nodes. On each node, run:

syncNode.sh <dmgr_host> <dmgr_port>

4. Start node agents and servers

Implementation for Standalone Profile:
1. Back up the existing configuration:

backupConfig.sh <backup_directory>

2. Enable FIPS 140-3.

Option A - Using Administrative Console:
1. Click Security >> SSL certificate and key management >> Manage FIPS.

2. Select "Enable FIPS 140-3".

3. Click "Apply".

Option B - Using Admin Command:
AdminTask.enableFips('[-enableFips true -fipsLevel FIPS140-3 ]')

For both methods, restart the application server.

Check Contents

Note: If FIPS 140-2 is configured in WBSP-AS-001290, this is not applicable. This is allowed until 21 September 2026. If FIPS 140-2 is still in use after this date, this is a finding.

From administrative console, click Security >> SSL certificate and key management >> Manage FIPS.

If "Enable FIPS 140-3" is not selected, this is a finding.

Vulnerability Number

V-283677

Documentable

False

Rule Version

WBSP-AS-001770

Severity Override Guidance

Note: If FIPS 140-2 is configured in WBSP-AS-001290, this is not applicable. This is allowed until 21 September 2026. If FIPS 140-2 is still in use after this date, this is a finding.

From administrative console, click Security >> SSL certificate and key management >> Manage FIPS.

If "Enable FIPS 140-3" is not selected, this is a finding.

Check Content Reference

M

Target Key

5510