STIGQter STIGQter: STIG Summary: IBM WebSphere Traditional V9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Aug 2018:

The WebSphere Application Server users in a LDAP user registry group must be authorized for that group.

DISA Rule

SV-95945r1_rule

Vulnerability Number

V-81231

Group Title

SRG-APP-000340-AS-000185

Rule Version

WBSP-AS-000240

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the LDAP server admin console, assign WebSphere users to the appropriate WebSphere group.

Check Contents

If a file based or local federated repository is in use, this requirement is NA.

Review System Security Plan documentation.

Interview the system administrator.

In the administrative console select Security >> Global Security.

Under "User Account Repository", verify the "Available realm Definition" is set to "Standalone LDAP registry".

Select "Configure".

The properties of the LDAP repository are displayed for purposes of identifying the LDAP server.

Work with the admin of LDAP repository.

Identify users and groups.

Validate members of groups are authorized.

If the group members have not been authorized by the ISSO/ISSM, this is a finding.

Vulnerability Number

V-81231

Documentable

False

Rule Version

WBSP-AS-000240

Severity Override Guidance

If a file based or local federated repository is in use, this requirement is NA.

Review System Security Plan documentation.

Interview the system administrator.

In the administrative console select Security >> Global Security.

Under "User Account Repository", verify the "Available realm Definition" is set to "Standalone LDAP registry".

Select "Configure".

The properties of the LDAP repository are displayed for purposes of identifying the LDAP server.

Work with the admin of LDAP repository.

Identify users and groups.

Validate members of groups are authorized.

If the group members have not been authorized by the ISSO/ISSM, this is a finding.

Check Content Reference

M

Target Key

3399

Comments