STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

The HTTP request message body size must be limited.

DISA Rule

SV-33008r1_rule

Vulnerability Number

V-13736

Group Title

WA000-WWA060

Rule Version

WA000-WWA060 W22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Specify a size for the LimitRequestBody directive.

Check Contents

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: LimitRequestBody

If the value of LimitRequestBody is not greater than 0 or does not exist, this is a finding.

Vulnerability Number

V-13736

Documentable

False

Rule Version

WA000-WWA060 W22

Severity Override Guidance

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: LimitRequestBody

If the value of LimitRequestBody is not greater than 0 or does not exist, this is a finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments