STIGQter STIGQter: STIG Summary: Oracle HTTP Server 12.1.3 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 24 Jul 2020:

OHS administration must be performed over a secure path or at the local console.

DISA Rule

SV-79179r1_rule

Vulnerability Number

V-64689

Group Title

SRG-APP-000516-WSR-000174

Rule Version

OH12-1X-000226

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure that both system and OHS administration are done through a secure path.

Check Contents

1. Check that if server administration is performed remotely, it will only be performed securely by system administrators.

2. Check that if OHS administration has been delegated, those users will be documented and approved by the ISSO.

3. Check that remote administration is in compliance with any requirements contained within the Unix Server STIGs and any applicable network STIGs.

4. Check that remote administration of any kind will be restricted to documented and authorized personnel and that all users performing remote administration are authenticated.

5. Check that all remote sessions will be encrypted and utilize FIPS 140-2 approved protocols.

6. If any of the above conditions are not met, this is a finding.

Vulnerability Number

V-64689

Documentable

False

Rule Version

OH12-1X-000226

Severity Override Guidance

1. Check that if server administration is performed remotely, it will only be performed securely by system administrators.

2. Check that if OHS administration has been delegated, those users will be documented and approved by the ISSO.

3. Check that remote administration is in compliance with any requirements contained within the Unix Server STIGs and any applicable network STIGs.

4. Check that remote administration of any kind will be restricted to documented and authorized personnel and that all users performing remote administration are authenticated.

5. Check that all remote sessions will be encrypted and utilize FIPS 140-2 approved protocols.

6. If any of the above conditions are not met, this is a finding.

Check Content Reference

M

Target Key

2753

Comments