STIGQter STIGQter: STIG Summary:

IBM WebSphere Liberty Server Security Technical Implementation Guide

Version: 2

Release: 4 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-250322r960735_ruleMaximum in-memory session count must be set according to application requirements.
SV-250323r960759_ruleThe WebSphere Liberty Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.
SV-250324r960762_ruleSecurity cookies must be set to HTTPOnly.
SV-250325r1015250_ruleThe WebSphere Liberty Server must log remote session and security activity.
SV-250326r1137578_ruleUsers in the REST API admin role must be authorized.
SV-250327r1043188_ruleThe WebSphere Liberty Server must be configured to offload logs to a centralized system.
SV-250328r960933_ruleThe WebSphere Liberty Server must protect log information from unauthorized access or changes.
SV-250329r960939_ruleThe WebSphere Liberty Server must protect log tools from unauthorized access.
SV-250330r960951_ruleThe WebSphere Liberty Server must be configured to encrypt log information.
SV-250331r960960_ruleThe WebSphere Liberty Server must protect software libraries from unauthorized access.
SV-250332r1043177_ruleThe WebSphere Liberty Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.
SV-250333r1051118_ruleThe WebSphere Liberty Server must use an LDAP user registry.
SV-250334r1051118_ruleBasic Authentication must be disabled.
SV-250335r1015469_ruleMultifactor authentication for network access to privileged accounts must be used.
SV-250336r1015470_ruleThe WebSphere Liberty Server must store only encrypted representations of user passwords.
SV-250337r961029_ruleThe WebSphere Liberty Server must use TLS-enabled LDAP.
SV-250338r961044_ruleThe WebSphere Liberty Server must use DoD-issued/signed certificates.
SV-250339r1193261_ruleThe WebSphere Liberty Server must use FIPS 140-2 approved encryption modules when authenticating users and processes.
SV-250340r1043182_ruleHTTP session timeout must be configured.
SV-250341r1015252_ruleApplication security must be enabled on the WebSphere Liberty Server.
SV-250342r961353_ruleUsers in a reader-role must be authorized.
SV-250343r961392_ruleThe WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
SV-250344r961461_ruleThe server.xml file must be protected from unauthorized modification.
SV-250345r961521_ruleThe WebSphere Liberty Server must prohibit the use of cached authenticators after an organization-defined time period.
SV-250346r1067567_ruleThe WebSphere Liberty Server LTPA keys password must be changed.
SV-250347r961632_ruleThe WebSphere Liberty Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.
SV-250348r1137581_ruleThe WebSphere Liberty Server must be configured to use HTTPS only.
SV-250349r1137612_ruleThe WebSphere Liberty Server must install security-relevant software updates within the time period directed by an authoritative source.
SV-250350r961812_ruleThe WebSphere Liberty Server must generate log records for authentication and authorization events.
SV-283668r1193262_ruleThe WebSphere Liberty Server must use FIPS 140-3-approved encryption modules when authenticating users and processes.