STIGQter STIGQter: STIG Summary: Oracle HTTP Server 12.1.3 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 24 Jul 2020:

OHS accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.

DISA Rule

SV-78939r1_rule

Vulnerability Number

V-64449

Group Title

SRG-APP-000211-WSR-000030

Rule Version

OH12-1X-000266

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Remove any accounts and privileges that are unnecessary for OHS to run or for other functionality provided by the server.

Check Contents

1. Get list of OS accounts, with associated privileges, from System Administrator.

2. Confirm that all accounts and privileges are needed and documented.

3. If not, this is a finding.

Vulnerability Number

V-64449

Documentable

False

Rule Version

OH12-1X-000266

Severity Override Guidance

1. Get list of OS accounts, with associated privileges, from System Administrator.

2. Confirm that all accounts and privileges are needed and documented.

3. If not, this is a finding.

Check Content Reference

M

Target Key

2753

Comments