STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-259137r1003685_ruleThe vCenter VAMI service must limit the number of allowed simultaneous session requests.
SV-259138r1003688_ruleThe vCenter VAMI service must use cryptography to protect the integrity of remote sessions.
SV-259139r1003691_ruleThe vCenter VAMI service must generate information to monitor remote access.
SV-259140r1003694_ruleThe vCenter VAMI service must produce log records containing sufficient information to establish what type of events occurred.
SV-259141r960930_ruleThe vCenter VAMI service log files must only be accessible by privileged users.
SV-259142r1210449_ruleThe vCenter VAMI service must off-load log records onto a different system or media from the system being logged.
SV-259143r1003697_ruleThe vCenter VAMI service must explicitly disable Multipurpose Internet Mail Extensions (MIME) mime mappings based on "Content-Type".
SV-259144r1003700_ruleThe vCenter VAMI service must have resource mappings set to disable the serving of certain file types.
SV-259145r1003703_ruleThe vCenter VAMI service must have Web Distributed Authoring (WebDAV) disabled.
SV-259146r1003706_ruleThe vCenter VAMI service must protect system resources and privileged operations from hosted applications.
SV-259147r961041_ruleThe vCenter VAMI service must restrict access to the web server's private key.
SV-259149r1003709_ruleThe vCenter VAMI service must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks.
SV-259150r1003712_ruleThe vCenter VAMI service must set the encoding for all text mime types to UTF-8.
SV-259151r1003715_ruleThe vCenter VAMI service must disable directory listing.
SV-259152r1003718_ruleThe vCenter VAMI service must not be configured to use the "mod_status" module.
SV-259153r1003721_ruleThe vCenter VAMI service must have debug logging disabled.
SV-259155r1003724_ruleThe vCenter VAMI service must disable client initiated TLS renegotiation.
SV-259156r1003727_ruleThe vCenter VAMI service must be configured to hide the server type and version in client responses.
SV-259157r1003730_ruleThe vCenter VAMI service must implement HTTP Strict Transport Security (HSTS).
SV-259158r1003733_ruleThe vCenter VAMI service must implement prevent rendering inside a frame or iframe on another site.
SV-259159r1003736_ruleThe vCenter VAMI service must protect against MIME sniffing.
SV-259160r1003739_ruleThe vCenter VAMI service must enable Content Security Policy.