STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Aug 2018:

The WebSphere Application Server Single Sign On (SSO) must have SSL enabled for Web and SIP Security.

DISA Rule

SV-95933r1_rule

Vulnerability Number

V-81219

Group Title

SRG-APP-000014-AS-000009

Rule Version

WBSP-AS-000180

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the administrative console, navigate to Security >> Global Security.

Expand "Web and SIP security".

Click on "Single sign-on (SSO)".

Select "Requires SSL".

Click "OK".

Click "Save".

Restart the DMGR and all the JVMs.

Check Contents

From the administrative console, navigate to Security >> Global Security.

Expand "Web and SIP security".

Click on "Single sign-on (SSO)".

If "requires SSL" is not selected, this is a finding.

Vulnerability Number

V-81219

Documentable

False

Rule Version

WBSP-AS-000180

Severity Override Guidance

From the administrative console, navigate to Security >> Global Security.

Expand "Web and SIP security".

Click on "Single sign-on (SSO)".

If "requires SSL" is not selected, this is a finding.

Check Content Reference

M

Target Key

3399

Comments