STIGQter STIGQter: STIG Summary: Oracle HTTP Server 12.1.3 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 24 Jul 2020:

Non-privileged accounts on the hosting system must only access OHS security-relevant information and functions through a distinct administrative account.

DISA Rule

SV-78993r1_rule

Vulnerability Number

V-64503

Group Title

SRG-APP-000340-WSR-000029

Rule Version

OH12-1X-000035

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Configure sudo such that only the account that owns the OHS software can access it from the hosting system.

Check Contents

1. Check that sudo is properly configured for the account owning the OHS software.

2. If accounts other than the account that owns the OHS software can access the OHS software, this is a finding.

Vulnerability Number

V-64503

Documentable

False

Rule Version

OH12-1X-000035

Severity Override Guidance

1. Check that sudo is properly configured for the account owning the OHS software.

2. If accounts other than the account that owns the OHS software can access the OHS software, this is a finding.

Check Content Reference

M

Target Key

2753

Comments