STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 26 Apr 2019:

Cookies exchanged between the web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies.

DISA Rule

SV-70263r2_rule

Vulnerability Number

V-56009

Group Title

SRG-APP-000439-WSR-000155

Rule Version

SRG-APP-000439-WSR-000155

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to encrypt cookies before transmission.

Check Contents

Review the web server documentation and deployed configuration to verify that cookies are encrypted before transmission.

If the web server is not configured to encrypt cookies, this is a finding.

Vulnerability Number

V-56009

Documentable

False

Rule Version

SRG-APP-000439-WSR-000155

Severity Override Guidance

Review the web server documentation and deployed configuration to verify that cookies are encrypted before transmission.

If the web server is not configured to encrypt cookies, this is a finding.

Check Content Reference

M

Target Key

2557

Comments