STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for UNIX Security Technical Implementation Guide Version: 1 Release: 11 Benchmark Date: 25 Jan 2019:

Web server options for the OS root must be disabled.

DISA Rule

SV-33213r1_rule

Vulnerability Number

V-26324

Group Title

WA00545

Rule Version

WA00545 A22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the root directory has the appropriate Options assignment.

Check Contents

Enter the following command:

more /usr/local/Apache2.2/conf/httpd.conf.

Review the httpd.conf file and search for the following directive:

Directory

For every root directory entry (i.e. <Directory />) ensure the following entry exists:

Options None

If the statement above is not found in the root directory statement, this is a finding.

If Allow directives are included in the root directory statement, this is a finding.

If the root directory statement is not found at all, this is a finding.

Vulnerability Number

V-26324

Documentable

False

Rule Version

WA00545 A22

Severity Override Guidance

Enter the following command:

more /usr/local/Apache2.2/conf/httpd.conf.

Review the httpd.conf file and search for the following directive:

Directory

For every root directory entry (i.e. <Directory />) ensure the following entry exists:

Options None

If the statement above is not found in the root directory statement, this is a finding.

If Allow directives are included in the root directory statement, this is a finding.

If the root directory statement is not found at all, this is a finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments