IBM WebSphere Traditional V9.x Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +77 −76
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 77
- V-255818 Medium The WebSphere Application Server maximum in-memory session count must be set according to application requirements.
- V-255819 Medium The WebSphere Application Server admin console session timeout must be configured.
- V-255820 Medium The WebSphere Application Server security auditing must be enabled.
- V-255821 Medium The WebSphere Application Server groups in the user registry mapped to WebSphere auditor roles must be configured in accordance with the security plan.
- V-255822 Medium The WebSphere Application Server users in the WebSphere auditor role must be configured in accordance with the System Security Plan.
- V-255823 Medium The WebSphere Application Server audit event type filters must be configured.
- V-255824 Medium The WebSphere Application Server audit service provider must be enabled.
- V-255825 Medium The WebSphere Application Server automatic repository checkpoints must be enabled to track configuration changes.
- V-255826 High The WebSphere Application Server administrative security must be enabled.
- V-255827 High The WebSphere Application Server bus security must be enabled.
- V-255828 Medium The WebSphere Application Server users in a local user registry group must be authorized for that group.
- V-255829 Medium The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.
- V-255830 High The WebSphere Application Server global application security must be enabled.
- V-255831 High The WebSphere Application Server Single Sign On (SSO) must have SSL enabled for Web and SIP Security.
- V-255832 Medium The WebSphere Application Server security cookies must be set to HTTPOnly.
- V-255833 High The WebSphere Application Server Java 2 security must be enabled.
- V-255834 High The WebSphere Application Server Java 2 security must not be bypassed.
- V-255835 Medium The WebSphere Application Server users in the admin role must be authorized.
- V-255836 Medium The WebSphere Application Server LDAP groups must be authorized for the WebSphere role.
- V-255837 Medium The WebSphere Application Server users in a LDAP user registry group must be authorized for that group.
- V-255838 Medium The WebSphere Application Server management interface must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
- V-255839 Medium The WebSphere Application Server management interface must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- V-255840 Low The WebSphere Application Server must generate log records when successful/unsuccessful attempts to access subject privileges occur.
- V-255841 Medium The WebSphere Application Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
- V-255842 Medium The WebSphere Application Server must allocate audit log record storage capacity in accordance with organization-defined log record storage requirements.
- V-255843 Medium The WebSphere Application Server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.
- V-255844 Low The WebSphere Application Server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
- V-255845 Medium The WebSphere Application Server audit subsystem failure action must be set to Log warning.
- V-255846 Low The WebSphere Application Server must shut down by default upon log failure (unless availability is an overriding concern).
- V-255847 Low The WebSphere Application Server high availability applications must be configured to fail over to another system in the event of log subsystem failure.
- V-255848 Low The WebSphere Application Server must be configured to protect log information from any type of unauthorized read access.
- V-255849 Medium The WebSphere Application Server must protect log information from unauthorized modification.
- V-255850 Medium The WebSphere Application Server must protect log information from unauthorized deletion.
- V-255851 Medium The WebSphere Application Server wsadmin file must be protected from unauthorized access.
- V-255852 Medium The WebSphere Application Server wsadmin file must be protected from unauthorized modification.
- V-255853 Medium The WebSphere Application Server wsadmin file must be protected from unauthorized deletion.
- V-255854 Medium The WebSphere Application Server must be configured to encrypt log information.
- V-255855 Medium The WebSphere Application Server must be configured to sign log information.
- V-255856 Medium The WebSphere Application Server process must not be started from the command line with the -password option.
- V-255857 Medium The WebSphere Application Server files must be owned by the non-root WebSphere user ID.
- V-255858 Low The WebSphere Application Server sample applications must be removed.
- V-255859 Low The WebSphere Application Server must remove JREs left by web server and plug-in installers for web servers and plugins running in the DMZ.
- V-255860 Medium The WebSphere Application Server must be run as a non-admin user.
- V-255861 Medium The WebSphere Application Server must disable JSP class reloading.
- V-255862 Medium The WebSphere Application Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.
- V-255863 Medium The WebSphere Application Server LDAP user registry must be used.
- V-255864 Medium The WebSphere Application Server local file-based user registry must not be used.
- V-255865 Medium The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
- V-255866 Medium The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.
- V-255867 Medium The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.
- V-255868 Medium The WebSphere Application Server must authenticate all network-connected endpoint devices before establishing any connection.
- V-255869 Medium The WebSphere Application Server must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
- V-255870 High The WebSphere Application Server application security must be enabled for each security domain except for publicly available applications specified in the System Security Plan.
- V-255871 High The WebSphere Application Server secure LDAP (LDAPS) must be used for authentication.
- V-255872 Medium The WebSphere Application Server must prohibit the use of cached authenticators after an organization-defined time period.
- V-255873 High The WebSphere Application Server default keystore passwords must be changed.
- V-255874 Medium The WebSphere Application Server must use signer for DoD-issued certificates.
- V-255875 Medium The WebSphere Application Server must utilize FIPS 140-2-approved encryption modules when authenticating users and processes.
- V-255876 Medium The WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.
- V-255877 Medium The WebSphere Application Server must use DoD-approved Signer Certificates.
- V-255878 Medium The WebSphere Application Servers must not be in the DMZ.
- V-255879 Medium The WebSphere Application Server DoD root CAs must be in the trust store.
- V-255880 Medium The WebSphere Application Server personal certificates in all keystores must be issued by an approved DoD CA.
- V-255881 Low The WebSphere Application Server must be configured to perform complete application deployments when using A/B clusters.
- V-255882 Low The WebSphere Application servers with an RMF categorization of high must be in a high-availability (HA) cluster.
- V-255883 Low The WebSphere Application Server must not generate LTPA keys automatically.
- V-255884 Low The WebSphere Application Server must periodically regenerate LTPA keys.
- V-255885 Medium The WebSphere Application Server high availability applications must be installed on a cluster.
- V-255886 Low The WebSphere Application Server memory session settings must be defined according to application load requirements.
- V-255887 Medium The WebSphere Application Server thread pool size must be defined according to application load requirements.
- V-255888 Medium The WebSphere Application Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.
- V-255889 Medium The WebSphere Application Server distribution and consistency services (DCS) transport links must be encrypted.
- V-255890 Medium The WebSphere Application Server plugin must be configured to use HTTPS only.
- V-255891 Medium The WebSphere Application Server must remove organization-defined software components after updated versions have been installed.
- V-255892 Medium The WebSphere Application Server must apply the latest security fixes.
- V-255893 Medium The WebSphere Application Server must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVMs, CTOs, DTMs, and STIGs).
- V-283677 Medium The WebSphere Application Server must use FIPS 140-3-approved encryption modules when authenticating users and processes.
Removed rules 76
- V-81193 Medium The WebSphere Application Server maximum in-memory session count must be set according to application requirements.
- V-81195 Medium The WebSphere Application Server admin console session timeout must be configured.
- V-81197 Medium The WebSphere Application Server automatic repository checkpoints must be enabled to track configuration changes.
- V-81199 High The WebSphere Application Server administrative security must be enabled.
- V-81201 High The WebSphere Application Server bus security must be enabled.
- V-81203 Medium The WebSphere Application Server security auditing must be enabled.
- V-81205 Medium The WebSphere Application Server groups in the user registry mapped to WebSphere auditor roles must be configured in accordance with the security plan.
- V-81207 Medium The WebSphere Application Server users in the WebSphere auditor role must be configured in accordance with the System Security Plan.
- V-81209 Medium The WebSphere Application Server audit event type filters must be configured.
- V-81211 Medium The WebSphere Application Server audit service provider must be enabled.
- V-81213 Medium The WebSphere Application Server users in a local user registry group must be authorized for that group.
- V-81215 Medium The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.
- V-81217 High The WebSphere Application Server global application security must be enabled.
- V-81219 High The WebSphere Application Server Single Sign On (SSO) must have SSL enabled for Web and SIP Security.
- V-81221 Medium The WebSphere Application Server security cookies must be set to HTTPOnly.
- V-81223 High The WebSphere Application Server Java 2 security must be enabled.
- V-81225 High The WebSphere Application Server Java 2 security must not be bypassed.
- V-81227 Medium The WebSphere Application Server users in the admin role must be authorized.
- V-81229 Medium The WebSphere Application Server LDAP groups must be authorized for the WebSphere role.
- V-81231 Medium The WebSphere Application Server users in a LDAP user registry group must be authorized for that group.
- V-81233 Medium The WebSphere Application Server management interface must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
- V-81235 Medium The WebSphere Application Server management interface must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- V-81237 Low The WebSphere Application Server must generate log records when successful/unsuccessful attempts to access subject privileges occur.
- V-81239 Medium The WebSphere Application Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
- V-81241 Medium The WebSphere Application Server must allocate audit log record storage capacity in accordance with organization-defined log record storage requirements.
- V-81243 Medium The WebSphere Application Server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.
- V-81245 Low The WebSphere Application Server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
- V-81247 Medium The WebSphere Application Server audit subsystem failure action must be set to Log warning.
- V-81249 Low The WebSphere Application Server must shut down by default upon log failure (unless availability is an overriding concern).
- V-81251 Low The WebSphere Application Server high availability applications must be configured to fail over to another system in the event of log subsystem failure.
- V-81253 Low The WebSphere Application Server must be configured to protect log information from any type of unauthorized read access.
- V-81255 Medium The WebSphere Application Server must protect log information from unauthorized modification.
- V-81257 Medium The WebSphere Application Server must protect log information from unauthorized deletion.
- V-81259 Medium The WebSphere Application Server wsadmin file must be protected from unauthorized access.
- V-81261 Medium The WebSphere Application Server wsadmin file must be protected from unauthorized modification.
- V-81263 Medium The WebSphere Application Server wsadmin file must be protected from unauthorized deletion.
- V-81265 Medium The WebSphere Application Server must be configured to encrypt log information.
- V-81267 Medium The WebSphere Application Server must be configured to sign log information.
- V-81269 Medium The WebSphere Application Server process must not be started from the command line with the -password option.
- V-81271 Medium The WebSphere Application Server files must be owned by the non-root WebSphere user ID.
- V-81273 Low The WebSphere Application Server sample applications must be removed.
- V-81275 Low The WebSphere Application Server must remove JREs left by web server and plug-in installers for web servers and plugins running in the DMZ.
- V-81277 Medium The WebSphere Application Server must be run as a non-admin user.
- V-81279 Medium The WebSphere Application Server must disable JSP class reloading.
- V-81293 Medium The WebSphere Application Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.
- V-81299 Medium The WebSphere Application Server LDAP user registry must be used.
- V-81305 Medium The WebSphere Application Server local file-based user registry must not be used.
- V-81311 Medium The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
- V-81325 Medium The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.
- V-81329 Medium The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.
- V-81333 Medium The WebSphere Application Server must authenticate all network-connected endpoint devices before establishing any connection.
- V-81341 Medium The WebSphere Application Server must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
- V-81343 High The WebSphere Application Server application security must be enabled for each security domain except for publicly available applications specified in the System Security Plan.
- V-81347 High The WebSphere Application Server secure LDAP (LDAPS) must be used for authentication.
- V-81351 Medium The WebSphere Application Server must prohibit the use of cached authenticators after an organization-defined time period.
- V-81357 High The WebSphere Application Server default keystore passwords must be changed.
- V-81361 Medium The WebSphere Application Server must use signer for DoD-issued certificates.
- V-81365 Medium The WebSphere Application Server must utilize FIPS 140-2-approved encryption modules when authenticating users and processes.
- V-81367 Medium The WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.
- V-81369 Medium The WebSphere Application Server must use DoD-approved Signer Certificates.
- V-81371 Medium The WebSphere Application Servers must not be in the DMZ.
- V-81373 Medium The WebSphere Application Server DoD root CAs must be in the trust store.
- V-81375 Medium The WebSphere Application Server personal certificates in all keystores must be issued by an approved DoD CA.
- V-81377 Low The WebSphere Application Server must be configured to perform complete application deployments when using A/B clusters.
- V-81379 Low The WebSphere Application servers with an RMF categorization of high must be in a high-availability (HA) cluster.
- V-81381 Low The WebSphere Application Server must not generate LTPA keys automatically.
- V-81383 Low The WebSphere Application Server must periodically regenerate LTPA keys.
- V-81385 Medium The WebSphere Application Server high availability applications must be installed on a cluster.
- V-81387 Low The WebSphere Application Server memory session settings must be defined according to application load requirements.
- V-81389 Medium The WebSphere Application Server thread pool size must be defined according to application load requirements.
- V-81391 Medium The WebSphere Application Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.
- V-81393 Medium The WebSphere Application Server distribution and consistency services (DCS) transport links must be encrypted.
- V-81395 Medium The WebSphere Application Server plugin must be configured to use HTTPS only.
- V-81397 Medium The WebSphere Application Server must remove organization-defined software components after updated versions have been installed.
- V-81399 Medium The WebSphere Application Server must apply the latest security fixes.
- V-81401 Medium The WebSphere Application Server must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVMs, CTOs, DTMs, and STIGs).
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- WBSP-AS-000010
- Vuln IDs
-
- V-255818
- V-81193
- Rule IDs
-
- SV-255818r960735_rule
- SV-95907
Checks: C-59491r876743_chk
Review system documentation. Identify the application session requirements. In the administrative console page, click Servers >> Server Types >> WebSphere application servers >> [server_name] >> Session management. Ensure the Maximum in-memory session count field is set to the number of sessions allowable. If not set according to application requirements, this is a finding.
Fix: F-59434r876744_fix
In the administrative console page, click Servers >> Server Types >> WebSphere application servers >> [server_name] >> Session management. Edit the Maximum in-memory session count field to be the number of sessions allowable.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- WBSP-AS-000020
- Vuln IDs
-
- V-255819
- V-81195
- Rule IDs
-
- SV-255819r1043182_rule
- SV-95909
Checks: C-59492r876746_chk
Review System Security Plan and system configuration documentation. Access the Deployment Manager (DMGR) operating system. Locate the deployment.xml file. The default file location where deployment.xml is installed are provided below. UNIX: /opt/IBM/WebSphere/Profiles/DefaultDmgr01/config/cells/<CELL NAME>/applications/isclite.ear/deployments/isclite/ Windows: C:\Program Files\IBM\WebSphere\Profiles\DefaultDmgr01\config\cells\<CELL NAME>\applications\isclite.ear\deployments\isclite\ Search the deployment.xml file for the string, "invalidationtimeout=" UNIX: grep -i invalidationtimeout $PATH/deployment.xml Windows: findstr -I invalidationtimeout= $PATH\deployment.xml The value is expressed in minutes and the default value is set to "30 minutes". If "invalidationtimeout" is not set to "10 minutes", this is a finding.
Fix: F-59435r876747_fix
Locate the deployment.xml file. The default file locations where deployment.xml is installed are provided below. UNIX: /opt/IBM/WebSphere/Profiles/DefaultDmgr01/config/cells/<CELL NAME>/applications/isclite.ear/deployments/isclite/ Windows: C:\Program Files\IBM\WebSphere\Profiles\DefaultDmgr01\config\cells\<CELL NAME>\applications\isclite.ear\deployments\isclite\ Make a backup copy of the deployment.xml file. Edit the deployment.xml file. Modify the "invalidationtimeout=" value and set to "10". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WBSP-AS-000070
- Vuln IDs
-
- V-255820
- V-81203
- Rule IDs
-
- SV-255820r960765_rule
- SV-95917
Checks: C-59493r876749_chk
In the administrative console, navigate to Security >> Security auditing. If "Enable security auditing" is not enabled, this is a finding.
Fix: F-59436r876750_fix
In the administrative console, navigate to Security >> Security auditing to enable. Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WBSP-AS-000080
- Vuln IDs
-
- V-255821
- V-81205
- Rule IDs
-
- SV-255821r960765_rule
- SV-95919
Checks: C-59494r876752_chk
Review System Security Plan documentation. Identify groups and roles. In the administrative console, navigate to Users and Groups >> Administrative Group Roles. Check the roles for each group and compare to System Security Plan. If any group is not authorized by the ISSO/ISSM to be in an auditor role, this is a finding.
Fix: F-59437r876753_fix
Document all groups in an Auditor role in the security plan. In the administrative console, navigate to Users and Groups >> Administrative group roles. If an unauthorized group is in the auditor role, remove the auditor role from the group. Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WBSP-AS-000090
- Vuln IDs
-
- V-255822
- V-81207
- Rule IDs
-
- SV-255822r960765_rule
- SV-95921
Checks: C-59495r876755_chk
Review System Security Plan documentation. Identify users and roles. In the administrative console, navigate to Users and Groups >> Administrative User Roles. Check the roles for each user. If any user is not authorized by the ISSO/ISSM to be in the role of an auditor, this is a finding.
Fix: F-59438r876756_fix
In the administrative console, navigate to Users and Groups >> Administrative User roles. If an unauthorized user is in the auditor role, remove the user from the auditor role. Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WBSP-AS-000100
- Vuln IDs
-
- V-255823
- V-81209
- Rule IDs
-
- SV-255823r960765_rule
- SV-95923
Checks: C-59496r876758_chk
In the administrative console, navigate to Security >> Security auditing >> Event type Filters. Verify the following events and outcomes are enabled in the "Events and Outcomes" box. Also note the name of the filter associated with these events. This name will be referenced in STIG ID WBSP-AS-000110. AUTHN: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT AUTHZ: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT AUTHN_TERMINATE: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT REPOSITORY_SAVE: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT If these audit filters are not configured in "Events and Outcomes", this is a finding.
Fix: F-59439r876759_fix
In the administrative console, navigate to Security >> Security auditing >> Event type Filters. Click the "New" button to create a new filter; give it a unique name. Select SECURITY_AUTHN, SECURITY_AUTHZ, SECURITY_AUTHN_TERMINATE, and ADMIN_REPOSITORY_SAVE from "Selectable events". Add them to the "Enabled events" box by clicking on the right arrow. Select INFO, ERROR, SUCCESS, DENIED, REDIRECT, and WARNING from the "Selectable event outcomes" box. Click the right arrow to fill in "Enabled events outcomes" box. Click "OK". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WBSP-AS-000110
- Vuln IDs
-
- V-255824
- V-81211
- Rule IDs
-
- SV-255824r960765_rule
- SV-95925
Checks: C-59497r876761_chk
In the administrative console, navigate to Security >> Security auditing >> Audit Service Provider [provider name]. Under "Enabled filters", determine if the filter name from select the name of the filter that was recorded from STIG ID WBSP-AS-000100. If the filter that was identified in STIG ID WBSP-AS-000100 is not enabled, this is a finding.
Fix: F-59440r876762_fix
In the administrative console, navigate to Security >> Security auditing >> Event type Filters. Identify and record the event type filter that contains the required "Events and Outcomes". In the administrative console, click on Security >> Security auditing >> Audit Service Provider [provider name]. Under "Selectable filters", select the filter that was previously identified and recorded. Click the right arrow to add it to the list. Click "OK". Click "Save" to save the changes. Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WBSP-AS-000120
- Vuln IDs
-
- V-255825
- V-81197
- Rule IDs
-
- SV-255825r960765_rule
- SV-95911
Checks: C-59498r876764_chk
Review System Security Plan documentation. Identify the required "Automatic CheckPoint Depth" setting that has been defined. From administrative console, click System administration >> Extended repository service. If "Enable automatic repository checkpoints" is not selected or if the "automatic checkpoint depth" is less than the number of saves defined in the System Security Plan, this is a finding.
Fix: F-59441r876765_fix
From administrative console click System administration >> Extended repository service >> Enable automatic repository checkpoints. Enter a "checkpoint depth value" according to the security plan. Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-002314
- Version
- WBSP-AS-000130
- Vuln IDs
-
- V-255826
- V-81199
- Rule IDs
-
- SV-255826r961278_rule
- SV-95913
Checks: C-59499r876767_chk
From the administrative console, click Security >> Global Security. If "Enable administrative security" is not selected, this is a finding.
Fix: F-59442r876768_fix
From the administrative console, click Security >> Global Security. Click "Enable administrative security". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-002315
- Version
- WBSP-AS-000140
- Vuln IDs
-
- V-255827
- V-81201
- Rule IDs
-
- SV-255827r961863_rule
- SV-95915
Checks: C-59500r876770_chk
Review System Security Plan documentation. Interview the system administrator. Identify the service integration buses configured on the WAS. If there are no service integration buses, this requirement is NA. From the administration console, navigate to Security >> Bus Security. For each service integration bus, if security is not enabled, this is a finding.
Fix: F-59443r876771_fix
From the administration console, navigate to Security >> Bus Security. For each service integration bus where security is not enabled, click on "Disabled". Click the check box to "Enable bus security". Configure the transport settings and authorization policies according to application security access requirements specified in the security plan.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WBSP-AS-000150
- Vuln IDs
-
- V-255828
- V-81213
- Rule IDs
-
- SV-255828r961278_rule
- SV-95927
Checks: C-59501r876773_chk
If the systems user registry is managed by LDAP, this requirement is NA. Review the System Security Plan documentation. Interview the system administrator. Obtain a list of authorized users. In the administrative console, navigate to Users and Groups >> Manage Groups. Select each group. Select the "Members" tab. Validate the members of the group are authorized. If users in the group are not authorized by the ISSO/ISSM, this is a finding.
Fix: F-59444r876774_fix
From administrative console, navigate to Users and Groups >> Administrative group roles. Note: names of the groups and the roles assigned to each group. Navigate back to User and Groups >> Manage Groups. Click on every group. For each group, click on users. If there is any user who does not belong to the group based on the roles assigned to the group, click on the checkbox next to the user. Click "Remove". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- WBSP-AS-000160
- Vuln IDs
-
- V-255829
- V-81215
- Rule IDs
-
- SV-255829r960759_rule
- SV-95929
Checks: C-59502r876776_chk
From the administrative console, navigate to Security >> SSL certificate and key management. Click "SSL configurations". Click on each SSL configuration to review. Under "Additional Properties", click "Quality of protection (QoP)" settings. If the "Protocol" field does not show "TLSv1.2 or greater", this is a finding.
Fix: F-59445r876777_fix
From the administrative console, navigate to Security >> SSL certificate and key management. Click "SSL configurations". Click on each SSL configuration. Under "Additional Properties", click "Quality of protection (QoP)" settings. At the "Protocol" pull-down menu, select "TLSv1.2 or greater". Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- WBSP-AS-000170
- Vuln IDs
-
- V-255830
- V-81217
- Rule IDs
-
- SV-255830r960759_rule
- SV-95931
Checks: C-59503r876779_chk
From the administrative console, navigate to Security >> Global Security. If "Enable administrative security" and "Enable application security" are not selected, this is a finding.
Fix: F-59446r876780_fix
From the administrative console, navigate to Security >> Global Security. Click on "Enable administrative security". Click on "Enable application security". Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- WBSP-AS-000180
- Vuln IDs
-
- V-255831
- V-81219
- Rule IDs
-
- SV-255831r960759_rule
- SV-95933
Checks: C-59504r876782_chk
From the administrative console, navigate to Security >> Global Security. Expand "Web and SIP security". Click on "Single sign-on (SSO)". If "requires SSL" is not selected, this is a finding.
Fix: F-59447r876783_fix
From the administrative console, navigate to Security >> Global Security. Expand "Web and SIP security". Click on "Single sign-on (SSO)". Select "Requires SSL". Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- WBSP-AS-000190
- Vuln IDs
-
- V-255832
- V-81221
- Rule IDs
-
- SV-255832r960762_rule
- SV-95935
Checks: C-59505r876785_chk
From the administrative console, navigate to Security >> Global Security. Expand "Web and SIP security". Click on "Single sign-on (SSO)". If "Set security cookies to HTTPOnly" is not selected, this is a finding.
Fix: F-59448r876786_fix
From the administrative console, navigate to Security >> Global Security. Expand "Web and SIP security". Select "Set security cookies to HTTPOnly". Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- WBSP-AS-000211
- Vuln IDs
-
- V-255833
- V-81223
- Rule IDs
-
- SV-255833r1137578_rule
- SV-95937
Checks: C-59506r876788_chk
From the admin console, select Security >> Global Security >> Java 2 Security. If "Use Java 2 security to restrict application access to local resources" is not selected, this is a finding.
Fix: F-59449r876789_fix
From the admin console, select Security >> Global Security >> Java 2 Security. Select the "Use Java 2 security to restrict application access to local resources" check box. Ensure the application security policies are defined and access permissions are granted accordingly. Policies are created and access is granted on an application by application basis. Application access to the underlying host is based upon application access requirements.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- WBSP-AS-000212
- Vuln IDs
-
- V-255834
- V-81225
- Rule IDs
-
- SV-255834r1137578_rule
- SV-95939
Checks: C-59507r876791_chk
If the system is a development or test system, this requirement is NA. From the admin console, select Servers >> Server Types >> WebSphere application servers. For each application server, select Server Infrastructure >> Administration >> Custom properties. If the "com.ibm.websphere.java2secman.norethrow" resource value exists and is set to "true", this is a finding.
Fix: F-59450r876792_fix
From the admin console, select Servers >> Server Types >> WebSphere application servers. For each application server, select Server Infrastructure >> Administration >> Custom properties. Delete the "com.ibm.websphere.java2secman.norethrow" resource value from production systems.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WBSP-AS-000220
- Vuln IDs
-
- V-255835
- V-81227
- Rule IDs
-
- SV-255835r1137578_rule
- SV-95941
Checks: C-59508r876794_chk
Review System Security Plan documentation. In the administrative console, navigate to Users and Groups >> Administrative user roles. If users assigned to the admin role are not authorized by the ISSO/ISSM, this is a finding.
Fix: F-59451r876795_fix
Navigate to User and Groups >> Administrative user roles. If an unauthorized user is assigned to the admin role, click on the user, remove admin rights and assign proper roles as defined in System Security Plan. Do not delete any user with the "Primary administrative user name" designation. Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WBSP-AS-000230
- Vuln IDs
-
- V-255836
- V-81229
- Rule IDs
-
- SV-255836r1137578_rule
- SV-95943
Checks: C-59509r876797_chk
Review System Security Plan documentation. Review details regarding LDAP groups that are mapped to WebSphere roles. In the administrative console, under Users and Groups >> Administrative group roles. If there is a LDAP group or groups assigned to a WebSphere role that has not been authorized by the ISSO/ISSM, this is a finding.
Fix: F-59452r876798_fix
Navigate to User and Groups >> Administrative group roles. If any group is assigned roles that the group should not have, click on the group. Assign only the role(s) the group should have. Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WBSP-AS-000240
- Vuln IDs
-
- V-255837
- V-81231
- Rule IDs
-
- SV-255837r961353_rule
- SV-95945
Checks: C-59510r876800_chk
If a file based or local federated repository is in use, this requirement is NA. Review System Security Plan documentation. Interview the system administrator. In the administrative console select Security >> Global Security. Under "User Account Repository", verify the "Available realm Definition" is set to "Standalone LDAP registry". Select "Configure". The properties of the LDAP repository are displayed for purposes of identifying the LDAP server. Work with the admin of LDAP repository. Identify users and groups. Validate members of groups are authorized. If the group members have not been authorized by the ISSO/ISSM, this is a finding.
Fix: F-59453r876801_fix
In the LDAP server admin console, assign WebSphere users to the appropriate WebSphere group.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- WBSP-AS-000310
- Vuln IDs
-
- V-255838
- V-81233
- Rule IDs
-
- SV-255838r960843_rule
- SV-95947
Checks: C-59511r876803_chk
Point browser to the URL of the WebSphere administration console. If the Standard Mandatory DoD Notice and Consent Banner is not displayed, this is a finding.
Fix: F-59454r876804_fix
Open the file ${WAS_HOME}/properties/login.info. Follow the instructions in the HTML comment section to create the pre-logon banner. Enter the Standard DoD Mandatory Notice and Consent banner into the HTML section. If logged on to the admin console, log out and log back on to validate the changes. Restart the DMGR and all the JVMs.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- WBSP-AS-000320
- Vuln IDs
-
- V-255839
- V-81235
- Rule IDs
-
- SV-255839r960846_rule
- SV-95949
Checks: C-59512r876806_chk
Point browser to the URL of the WebSphere administration console. If the Standard Mandatory DoD Notice and Consent Banner is not retained until the user acknowledges the usage conditions, this is a finding.
Fix: F-59455r876807_fix
Open the file ${WAS_HOME}/properties/login.info. Follow the instructions in the HTML comment section to create the pre-logon banner. Enter the Standard DoD Mandatory Notice and Consent banner into the HTML section. If logged on to the admin console, log out and log back on to validate the changes. Restart the DMGR and all the JVMs.
- RMF Control
- AU-12
- Severity
- L
- CCI
- CCI-000172
- Version
- WBSP-AS-000380
- Vuln IDs
-
- V-255840
- V-81237
- Rule IDs
-
- SV-255840r960885_rule
- SV-95951
Checks: C-59513r876809_chk
In the administrative console, navigate to Security >> Security auditing >> Audit Service Provider. Click on the providers in the list. Note: names of all the filters, e.g., "DefaultAuditSpecification_1". Go back to Security >> Security auditing >> Event type Filters. Find the filters previously noted. If you do not see the filter for SECURITY_AUTHN, SECURITY_AUTHZ, SECURITY_AUTHN_TERMINATE, and ADMIN_REPOSITORY_SAVE that has INFO, ERROR, SUCCESS, DENIED, REDIRECT, and WARNING defined, this is a finding.
Fix: F-59456r876810_fix
In the administrative console, navigate to Security >> Security auditing >> Audit Service Provider. Click on the providers in the list. Note the names of all the filters, e.g., "DefaultAuditSpecification_1". Go back to Security >> Security auditing >> Event type Filters. Find the filters previously noted. If you do not see that the provider filter for SECURITY_AUTHN, SECURITY_AUTHZ, SECURITY_AUTHN_TERMINATE, and ADMIN_REPOSITORY_SAVE that has INFO, ERROR, SUCCESS, DENIED, REDIRECT, and WARNING defined, click the "New" button to create a new filter. Give it a unique name. Select "SECURITY_AUTHN" and "ADMIN_REPOSITORY_SAVE" from the "Events to associate with audit filter" field. Click the right arrow to fill in "Enabled events" field. From "Event outcomes to associate with an audit filter" field, select INFO, ERROR, SUCCESS, DENIED, REDIRECT, and WARNING. Click the right arrow to fill in "Enabled event outcomes" field. Click "OK". Go back to Security >> Security auditing >> Audit Service Provider >> [provider]. Under "Selectable filters", select the new filter just created. Click the right arrow to add it to the list. Click "OK". Click "Save". Restart the DMGR and all the JVMs.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WBSP-AS-000580
- Vuln IDs
-
- V-255841
- V-81239
- Rule IDs
-
- SV-255841r961392_rule
- SV-95953
Checks: C-59514r876812_chk
Review System Security Plan documentation. Identify the JVM log size and rotation settings based on component log policy. From the administrative console, navigate to Troubleshooting >> Logs and Trace. Choose [server name]. Click on the server name to select it. Click "JVM" Logs. For "System.out" verify "File Size" is selected and "Maximum size" and "Maximum Historical Log Files" are set according to the System Security Plan. For "System.err" verify "File Size" is selected and "Maximum size" and "Maximum Historical Log Files" are set according to the System Security Plan. If log size and log history retention settings for "System.err" and "System.out" are not set as per the System Security Plan, this is a finding.
Fix: F-59457r876813_fix
Identify JVM log size and history retention based on component log policy. Document those values in the System Security Plan. From the administrative console, navigate to Troubleshooting >> Logs and Trace. Select each [server name]. Click "JVM" Logs. Under "System.out", "Log Rotation", select "File size" in the "Maximum Size" entry field, enter the maximum log size based on policy. Under "System.err", "Log Rotation", select "File Size" in the "Maximum Size" entry field, enter the maximum log size based on policy. Click "OK". Click "Save".
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WBSP-AS-000590
- Vuln IDs
-
- V-255842
- V-81241
- Rule IDs
-
- SV-255842r961392_rule
- SV-95955
Checks: C-59515r876815_chk
Review System Security Plan documentation. Identify the Audit Service Provider log size and rotation settings based on component log policy. From administrative console, click Security >> Security auditing >> Audit service provider. Select each [audit_service_provider_name]. If "Audit Log Size" and "Max Number of Audit Log Files" are not configured as per the System Security Plan, this is a finding.
Fix: F-59458r876816_fix
Identify Audit Service Provider log size and history retention based on component log policy. Document those values in the System Security Plan. From administrative console, click Security >> Security auditing >>Related Items>> Audit service provider >> [audit_service_provider_name]. Under Audit log file size specify the size of the file in MB as defined by your policy. Under "Maximum number of audit logs files", specify the maximum number of logs you want to keep on the file system as defined by your policy. Click "OK". Click "Save".
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001858
- Version
- WBSP-AS-000630
- Vuln IDs
-
- V-255843
- V-81243
- Rule IDs
-
- SV-255843r961401_rule
- SV-95957
Checks: C-59516r876818_chk
If notifications of log processing failures are done via an alternative notification process, this is not a finding. In the administrative console, navigate to Security >> Security auditing >> Audit monitor. If "Enabled monitoring" is not checked and "Monitor notification" is not set to a name in the notifications list, this is a finding.
Fix: F-59459r876819_fix
Establish and utilize a notification process for WebSphere log events or configure WebSphere to send log events alerts via email. In the administrative console, navigate to Security >> Security auditing >> Audit monitor. Select a "Monitor" notification from the dropdown box or create a new notification. Click on "New". Specify a unique name for the new notification. Click "Message log" checkbox. Select "Email sent to notification list". Enter emails in the "Email address to add" field. Enter the mail server address in the "Outgoing mail (STMP) server" field. Click ">" to put email in "List of email addresses" field. Click "OK". Select the "Enable monitoring" check box to turn on audit failure notifications. Select the notification configuration to be used from the "Monitor notification" dropdown menu. Click "OK". Click "Save".
- RMF Control
- AU-5
- Severity
- L
- CCI
- CCI-000139
- Version
- WBSP-AS-000640
- Vuln IDs
-
- V-255844
- V-81245
- Rule IDs
-
- SV-255844r960912_rule
- SV-95959
Checks: C-59517r876821_chk
If the SA and ISSO are notified of log processing failures via an alternative notification process, this is not a finding. In the administrative console, navigate to Security >> Security auditing >> Audit monitor. If "Enabled monitoring" is not checked and "Monitor notification" is not set to a notification in the notifications list, that includes the SA and ISSO, this is a finding.
Fix: F-59460r876822_fix
Establish and utilize a notification process for WebSphere log events or configure WebSphere to send log event alerts via email. In the administrative console, navigate to Security >> Security auditing >> Audit monitor. Click on "New" button. Specify a unique name for the new notification name. Click "Message log" checkbox. Select "Email sent to notification list". Enter SA and ISSO emails in the "Email address to add" field. Enter the mail server address in the "Outgoing mail (STMP) server" field. Click ">" to put email in "List of email addresses" field. Click "OK". Select the "Enable monitoring" check box to turn on audit failure notifications. Select the notification configuration to be used from the "Monitor notification" dropdown menu. Click "OK". Click "Save".
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- WBSP-AS-000650
- Vuln IDs
-
- V-255845
- V-81247
- Rule IDs
-
- SV-255845r960912_rule
- SV-95961
Checks: C-59518r876824_chk
In the administrative console, navigate to Security >> Security auditing. If "Audit subsystem failure action" is not set to "Log Warning", this is a finding.
Fix: F-59461r876825_fix
In the administrative console, navigate to Security >> Security auditing. Click the "Audit subsystem failure action" dropdown box. Select "Log Warning". Click "Apply". Click "Save" to save the configuration. Restart the DMGR and all JVMs.
- RMF Control
- AU-5
- Severity
- L
- CCI
- CCI-000140
- Version
- WBSP-AS-000660
- Vuln IDs
-
- V-255846
- V-81249
- Rule IDs
-
- SV-255846r1043188_rule
- SV-95963
Checks: C-59519r876827_chk
If the System Security Plan documentation specifies system availability is an overriding concern, this requirement is NA. In the admin console click Security >> Security Auditing. If "Audit subsystem failure action" is not set to "Terminate", this is a finding.
Fix: F-59462r876828_fix
In the admin console click Security >> Security Auditing. Set "Audit subsystem failure action" to "Terminate". Restart the DMGR and all JVMs.
- RMF Control
- AU-5
- Severity
- L
- CCI
- CCI-000140
- Version
- WBSP-AS-000670
- Vuln IDs
-
- V-255847
- V-81251
- Rule IDs
-
- SV-255847r1043188_rule
- SV-95965
Checks: C-59520r876830_chk
If the System Security Plan documentation does not require redundancy, this requirement is NA. Click Servers >> Clusters >> WebSphere application server clusters. Ensure you have a cluster defined for every application requiring redundancy. If there is not a cluster defined for every application requiring redundancy, this is a finding.
Fix: F-59463r876831_fix
In the admin console, Click Servers >> Clusters >> WebSphere application server clusters. Define a cluster for every high availability application as outlined in the System Security Plan documentation. Refer to vendor documentation for steps on creating a fail over cluster.
- RMF Control
- AU-9
- Severity
- L
- CCI
- CCI-000162
- Version
- WBSP-AS-000740
- Vuln IDs
-
- V-255848
- V-81253
- Rule IDs
-
- SV-255848r960930_rule
- SV-95967
Checks: C-59521r876833_chk
Review system documentation and System Security Plan. Identify the home folder and user account for the WebSphere installation. Log on to the operating system that is hosting the WebSphere application server. By default, WebSphere will be installed in the "/opt/IBM/Websphere" folder on UNIX like systems and in the "C:\Program Files\IBM\Websphere\" folder on Windows systems. On UNIX systems, verify file permissions for the "WebSphere" folder are set to "770" for the WebSphere user, group, and other. Permissions do not propagate to sub-folders. On Windows systems, verify file permissions for "WebSphere" folder allow SYSTEM, WebSphere User and Admin Group full control. Permissions do not propagate to sub-folders. If file permissions exceed these restrictions, this is a finding.
Fix: F-59464r876834_fix
On the system hosting the WebSphere application server, log on to the operating system with admin rights. Navigate to the WebSphere folder, change permissions on the folder. Do not propagate permissions to sub-folders. For UNIX systems: set "WebSphere" folder permissions to "770". For Windows systems: set "WebSphere" folder permission to allow full control for SYSTEM, WebSphere user and Admin Group. Do not propagate permissions to sub-folders.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- WBSP-AS-000750
- Vuln IDs
-
- V-255849
- V-81255
- Rule IDs
-
- SV-255849r960933_rule
- SV-95969
Checks: C-59522r876836_chk
Review System Security Plan and the system documentation. Identify the home folder and user account for the WebSphere installation. Log on to the operating system that is hosting the WebSphere application server. By default, WebSphere will be installed in the "/opt/IBM/Websphere" folder on UNIX like systems and in the "C:\Program Files\IBM\Websphere\" folder on Windows systems. On UNIX systems, verify file permissions for the "WebSphere" folder are set to "770" for the WebSphere user, group and other. Permissions do not propagate to sub-folders. On Windows systems, verify file permissions for "WebSphere" folder allow SYSTEM, WebSphere User, and Admin Group full control. Permissions do not propagate to sub-folders. If file permissions exceed these restrictions, this is a finding.
Fix: F-59465r876837_fix
On the system hosting the WebSphere application server, log on to the operating system with admin rights. Navigate to the "WebSphere" folder, change permissions on the folder. Do not propagate permissions to sub-folders. For UNIX systems: set "WebSphere folder" permissions to "770". For Windows systems: set "WebSphere folder" permission to allow full control for SYSTEM, WebSphere user, and Admin Group. Do not propagate permissions to sub-folders.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- WBSP-AS-000760
- Vuln IDs
-
- V-255850
- V-81257
- Rule IDs
-
- SV-255850r960936_rule
- SV-95971
Checks: C-59523r876839_chk
Review System Security Plan and the system documentation. Identify the home folder and user account for the WebSphere installation. Log on to the operating system that is hosting the WebSphere application server. By default, WebSphere will be installed in the "/opt/IBM/Websphere" folder on UNIX like systems and in the "C:\Program Files\IBM\Websphere\" folder on Windows systems. On UNIX systems, verify file permissions for the "WebSphere" folder are set to "770" for the WebSphere user, group, and other. Permissions do not propagate to sub-folders. On Windows systems, verify file permissions for "WebSphere" folder allow SYSTEM, WebSphere User and Admin Group full control. Permissions do not propagate to sub-folders. If file permissions exceed these restrictions, this is a finding.
Fix: F-59466r876840_fix
On the system hosting the WebSphere application server, log on to the operating system with admin rights. Navigate to the WebSphere folder, change permissions on the folder. Do not propagate permissions to sub-folders. For UNIX systems: set "WebSphere" folder permissions to "770". For Windows systems: set "WebSphere" folder permission to allow full control for SYSTEM, WebSphere user, and Admin Group. Do not propagate permissions to sub-folders.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001493
- Version
- WBSP-AS-000770
- Vuln IDs
-
- V-255851
- V-81259
- Rule IDs
-
- SV-255851r960939_rule
- SV-95973
Checks: C-59524r876842_chk
Review System Security Plan and the system documentation. Identify the home folder and user account for the WebSphere installation. Log on to the operating system that is hosting the WebSphere application server. By default, WebSphere will be installed in the "/opt/IBM/Websphere" folder on UNIX like systems and in the "C:\Program Files\IBM\Websphere\" folder on Windows systems. On UNIX systems, verify file permissions for the "WebSphere" folder are set to "770" for the WebSphere user, group, and other. Permissions do not propagate to sub-folders. On Windows systems, verify file permissions for "WebSphere" folder allow SYSTEM, WebSphere User, and Admin Group full control. Permissions do not propagate to sub-folders. If file permissions exceed these restrictions, this is a finding.
Fix: F-59467r876843_fix
On the system hosting the WebSphere application server, log on to the operating system with admin rights. Navigate to the "WebSphere" folder, and change permissions on the folder. Do not propagate permissions to sub-folders. For UNIX systems: set the "WebSphere" folder permissions to "770". For Windows systems: set the "WebSphere" folder permission to allow full control for SYSTEM, WebSphere user, and Admin Group. Do not propagate permissions to sub-folders.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001494
- Version
- WBSP-AS-000780
- Vuln IDs
-
- V-255852
- V-81261
- Rule IDs
-
- SV-255852r960942_rule
- SV-95975
Checks: C-59525r876845_chk
Review System Security Plan and the system documentation. Identify the home folder and user account for the WebSphere installation. Log on to the operating system that is hosting the WebSphere application server. By default, WebSphere will be installed in the "/opt/IBM/Websphere" folder on UNIX like systems and in the "C:\Program Files\IBM\Websphere\" folder on Windows systems. On UNIX systems, verify file permissions for the "WebSphere" folder are set to "770" for the WebSphere user, group, and other. Permissions do not propagate to sub-folders. On Windows systems, verify file permissions for "WebSphere" folder allow SYSTEM, WebSphere User, and Admin Group full control. Permissions do not propagate to sub-folders. If file permissions exceed these restrictions, this is a finding.
Fix: F-59468r876846_fix
On the system hosting the WebSphere Application Server, log on to the operating system with admin rights. Navigate to the "WebSphere" folder. Change the permissions on the folder. Do not propagate permissions to sub-folders. For UNIX systems: set the "WebSphere" folder permissions to "770". For Windows systems: set the "WebSphere" folder permission to allow full control for SYSTEM, WebSphere user, and Admin Group. Do not propagate permissions to sub-folders.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001495
- Version
- WBSP-AS-000790
- Vuln IDs
-
- V-255853
- V-81263
- Rule IDs
-
- SV-255853r960945_rule
- SV-95977
Checks: C-59526r876848_chk
Review system documentation and security plan. Identify the home folder and user account for the WebSphere installation. Log on to the operating system that is hosting the WebSphere application server. By default, WebSphere will be installed in the "/opt/IBM/Websphere" folder on UNIX like systems and in the "C:\Program Files\IBM\Websphere\" folder on Windows systems. On UNIX systems, verify file permissions for the "WebSphere" folder are set to "770" for the WebSphere user, group, and other. Permissions do not propagate to sub-folders. On Windows systems, verify file permissions for WebSphere folder allow SYSTEM, WebSphere User, and Admin Group full control. Permissions do not propagate to sub-folders. If file permissions exceed these restrictions, this is a finding.
Fix: F-59469r876849_fix
On the system hosting the WebSphere application server, log on to the operating system with admin rights. Navigate to the "WebSphere" folder, change permissions on the folder. Do not propagate permissions to sub-folders. For UNIX systems: set the "WebSphere" folder permissions to "770". For Windows systems: set "WebSphere" folder permission to allow full control for SYSTEM, WebSphere user, and Admin Group. Do not propagate permissions to sub-folders.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001350
- Version
- WBSP-AS-000810
- Vuln IDs
-
- V-255854
- V-81265
- Rule IDs
-
- SV-255854r960951_rule
- SV-95979
Checks: C-59527r876851_chk
Review System Security Plan documentation. If the System Security Plan does not specify the encryption of audit records, this requirement is NA. From the administrative console, click Security >> Security Auditing >> Audit record encryption configuration. If the "Enable encryption" check box is not selected, this is a finding.
Fix: F-59470r876852_fix
From the administrative console, click Security >> Security Auditing >> Audit record encryption configuration. Select the "Enable encryption" checkbox. Select the keystore that contains the encrypting certificate from the drop-down menu or click "New" to create a new keystore. If you are using an existing certificate to encrypt your audit records, ensure the Certificate in the keystore is selected and specify the intended certificate in the "Certificate alias" drop-down menu. If you are generating a new certificate to encrypt your audit records, do NOT use the "Create a new certificate in the selected keystore" option, this will generate a SHA-1 signed certificate, which is not allowed. Instead, select Security >> SSL Certificate and key management >> KeyStores and Certificates. Select the keystore that is associated with the server hosting the audit logs. Select "Personal Certificates". Select "Create". Select either a CA-Signed or Chained Certificate based on your requirements. Fill in the information required to generate the certificate. Restart the DMGR and all the JVMs.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001350
- Version
- WBSP-AS-000820
- Vuln IDs
-
- V-255855
- V-81267
- Rule IDs
-
- SV-255855r960951_rule
- SV-95981
Checks: C-59528r876854_chk
From the administrative console, click Security >> Security Auditing >> Audit record signing configuration. If the "Enable signing" checkbox is not selected, this is a finding.
Fix: F-59471r876855_fix
From the administrative console, click Security >> Security Auditing >> Audit record signing configuration. Select the "Enable signing" checkbox. Select the keystore that contains the encrypting certificate from the drop-down menu. If you are using an existing certificate to sign your audit records, ensure the Certificate in keystore is selected and specify the intended certificate in the "Certificate alias" drop-down menu. If you are generating a new certificate to sign your audit records, do NOT use the "Create a new certificate in the selected keystore" option, this will generate a SHA-1 signed certificate, which is not allowed. Instead, select Security >> SSL Certificate and key management >> KeyStores and Certificates. Select the keystore that is associated with the server hosting the audit logs. Select "Personal Certificates". Select "Create". Select either a CA-Signed or Chained Certificate based on your requirements. Fill in the information required to generate the certificate. Restart the DMGR and all the JVMs.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WBSP-AS-000910
- Vuln IDs
-
- V-255856
- V-81269
- Rule IDs
-
- SV-255856r960963_rule
- SV-95983
Checks: C-59529r876857_chk
Review System Security Plan documentation. Interview the system administrator. Access operating system to list commands currently running. For UNIX: run "ps -ef | grep -i wsadmin.sh" For windows: from a DOS prompt as admin user run "WMIC path win32_process where "caption='wsadmin.exe'" get CommandLine" If the results show "wsadmin.sh(exe) -user <username> -password <password>", this is a finding.
Fix: F-59472r876858_fix
When starting WebSphere commands, such as wsadmin, stopManager, stopNode, stopServer, or syncNode; do not use the "-password <password>" option. Use the interactive mode instead; you will be prompted for user id and password. For scripts, you may configure user id and password in the "connector properties" files. These files are under "Profile_Root/Properties" folder. - soap.client.props: for default SOAP - sas.client.props : for RMI and JSR160RMI connectors - ipc.client.props: for IPC connector
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WBSP-AS-000920
- Vuln IDs
-
- V-255857
- V-81271
- Rule IDs
-
- SV-255857r960963_rule
- SV-95985
Checks: C-59530r876860_chk
Review System Security Plan documentation. Interview the system administrator. Determine the OS user and group information associated with the WebSphere processes. Identify the paths, files, and folders associated with the WebSphere installation. These include: - <WAS_HOME>: where you installed WebSphere. <WAS_HOME> default location: For UNIX: /opt/IBM/WebSphere/AppServer For Windows: C:\Program Files\IBM\WebSphere\AppServer - <PROFILE_HOME>: where the appserver instance resides. The default location is under "<WAS_HOME>/profiles". - <OTHER_HOME>: any additional files that may reside outside of <WAS_HOME>. Examples include: - shared library .jar files - Resource Adapter .rar files - Key and trust store files (.jks and .p12) - Other files such as jdbc drivers For Linux, use the command "find <directory> -user root" to find files owned by root user. On windows use the "dir /Q /S" command from the root directories to show the owners of all files. Examine the output for files owned by the administrator or root account. If any WebSphere file or additional files as described above are owned by root or the administrator, this is a finding.
Fix: F-59473r876861_fix
Note: executing this fix without proper planning regarding file ownership can render your installation inoperable. See vulnerability discussion before executing this fix. Ensure all WebSphere related files and folders are owned by the WebSphere OS user. Ensure OS group membership is restricted. File ownership changes for UNIX systems: chown -R <user> <WAS_HOME> chown -R <user> <PROFILE_HOME>, chown -R <user> <OTHER_HOME>, <OTHER_HOME> may be zero or more directories for other files Group ownership changes for UNIX systems: chgrp -R <user> <WAS_HOME> chgrp -R <user> <PROFILE_HOME>, chgrp -R <user> <OTHER_HOME>, where <OTHER_HOME> may be zero or more root directories for other files File ownership changes for Windows systems: "takeown /r /u <user> /f <directory /p <password of user>", where the <directory> is <WAS_HOME>, <PROFILE_HOME>, or <OTHER_HOME>
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WBSP-AS-000930
- Vuln IDs
-
- V-255858
- V-81273
- Rule IDs
-
- SV-255858r960963_rule
- SV-95987
Checks: C-59531r876863_chk
Navigate to Applications >> All Applications. Review all applications installed on the application server. If the sample applications snoop, ivt, or DefaultApplication are installed on a production system, this is a finding.
Fix: F-59474r876864_fix
Navigate to Applications >> All Applications. Click on the corresponding application checkbox. Select "Remove". Click "OK". Click "Save".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WBSP-AS-000940
- Vuln IDs
-
- V-255859
- V-81275
- Rule IDs
-
- SV-255859r960963_rule
- SV-95989
Checks: C-59532r876866_chk
This check needs to be run on the web server operating in the DMZ. Review system documentation. Identify web servers operating in DMZ. If there are no web servers configured for the DMZ, this is not applicable. From the administrative console, select Server Types >> Web Servers. Select each web server operating in the DMZ. Identify the "Web server installation location". Open a secured command shell to the web server in the DMZ. Change directory to the web server installation location. CD to the /plugins folder. If a /java directory exists in the plugins folder, this is a finding.
Fix: F-59475r876867_fix
For web servers provided with the WebSphere installation that are operating in the DMZ. Remove the /java directory from within the plugins folder.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WBSP-AS-000960
- Vuln IDs
-
- V-255860
- V-81277
- Rule IDs
-
- SV-255860r960963_rule
- SV-95991
Checks: C-59533r876869_chk
Interview systems manager. Identify the OS user ID that the WAS server runs as. Using relevant OS commands review OS processes and search for WAS processes (running as Java). Ensure they are running under the assigned non-administrative user id. For UNIX: "ps -ef|grep -i websphere" For Windows: "wmic path win32_process where "caption = 'java.exe'" get CommandLine If the WebSphere processes are running as the root or administrator user, this is a finding.
Fix: F-59476r876870_fix
Ensure that WAS processes are started via the specified non-privileged OS user ID when running commands such as startManager, startNode, and startServer. If startManager and startNode are in the system startup scripts, ensure that they are not started as the root user or admin user for Windows systems. For example, in the UNIX system, the inittab entry may look like: "was:235:respawn:/usr/WebSphere/AppServer/bin/rc.was >/dev/console 2>&1". Ensure the user is not a root user and is instead a regular OS user.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WBSP-AS-000970
- Vuln IDs
-
- V-255861
- V-81279
- Rule IDs
-
- SV-255861r960963_rule
- SV-95993
Checks: C-59534r876872_chk
From admin console, navigate to: Applications >> All applications >> [application name] >> JSP and JSP options. If "JSP enable class reloading" is checked, this is a finding.
Fix: F-59477r876873_fix
To disable JSP reloading: From the admin console, navigate to: Applications >> All applications >> [application name] >> JSP and JSP options. Uncheck "JSP enable class reloading".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WBSP-AS-000980
- Vuln IDs
-
- V-255862
- V-81293
- Rule IDs
-
- SV-255862r1043177_rule
- SV-96007
Checks: C-59535r876875_chk
In the administrative console, click Servers >> All Servers. Select each [server_name]. Select >> Ports. Confirm server ports are registered with PPSM. Navigate to System Administration >> Deployment Manager >> Ports. Confirm ports are registered with PPSM. Navigate to System Administration >> node agents. For each [node agent], select >> Ports. Confirm ports are registered with PPSM. If any of available ports are not registered with PPSM, or if those ports to be connected through the firewall are not approved by PPSM, this is a finding.
Fix: F-59478r876876_fix
Ensure all available ports are registered with PPSM.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- WBSP-AS-001010
- Vuln IDs
-
- V-255863
- V-81299
- Rule IDs
-
- SV-255863r1051118_rule
- SV-96013
Checks: C-59536r876878_chk
In the administrative console, click Security >> Global security. If the "Available realm definitions" drop down box under the "User account repository" section is not set to "Standalone LDAP registry", this is a finding.
Fix: F-59479r876879_fix
In the administrative console, click Security >> Global security. Under "User account repository", click the "Available realm definitions" drop-down list. Select "Standalone LDAP" registry. Click "Configure". Provide the Primary Administrative user name, type of LDAP server, hostname for the LDAP server, define the Base distinguished name. Click "OK". On "Global security" panel, click "Set as current". Click "Apply". Click "Save". Recycle and synchronize the JVMS.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- WBSP-AS-001020
- Vuln IDs
-
- V-255864
- V-81305
- Rule IDs
-
- SV-255864r1051118_rule
- SV-96019
Checks: C-59537r876881_chk
Navigate to Security >> Global Security. Under "User Account Repository" if the "Federated Repositories" is chosen, click on "Configure". Under "Repositories in the realm", if "o=defaultWIMFileBasedRealm" appears in the "Base Entry" column, this is a finding.
Fix: F-59480r876882_fix
Navigate to Security >> Global Security. Under "User Account Repository", select "Stand alone LDAP" from the "Available realm definitions" drop-down. Click on "Configure". Select an existing user from the LDAP directory to be the primary WebSphere admin user. Identify the type of LDAP server; specify an IP or DNS name for the LDAP Server, and the port used to connect to the LDAP server. Specify BASE DN. Specify the BIND DN. Specify the BIND Password. Select the "SSL enabled" check box to use secure LDAP. Click "Apply". Click "Save". Go to Global Security. Select "Standalone LDAP registry" from the "Available realm definitions" drop-down. Click "Set as current". Click "Apply". Click "Save". Restart the dmgr and synchronize the JVMs.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- WBSP-AS-001030
- Vuln IDs
-
- V-255865
- V-81311
- Rule IDs
-
- SV-255865r960972_rule
- SV-96025
Checks: C-59538r876884_chk
Check that the admin console is enabled for client certificate logon. In the Deployment Manager, check the file on: <WAS_INSTALL>/profiles/<profileName>/config/cells/<cellName>/applications/isclite.ear/deployments/isclite/isclite.war/WEB-INF/web.xml. If the "XML element <auth-method>FORM</auth-method>" is present, this is a finding.
Fix: F-59481r876885_fix
From the admin console, select System Administration >> Deployment Manager >> Java and Process Management >> Process definition >> Java Virtual Machine >> Custom Properties. Select "New". Insert the following case sensitive value into the "Name" field: "adminconsole.certLogin". Select "Value". Enter "true". Click "Apply". Click "Save". Select Security >> SSL Certificate and Key management >> SSL Configurations >> Select CellDefaultSSLSettings >> Quality of Protection (QOP) settings. In the "Client Authentication" drop-box, make sure "Supported" or "Required" is selected. Click "Apply". Click "Save". Save a backup copy and edit the "Web.xml" file as follows: <WAS_INSTALL>/profiles/<profileName>/config/cells/<cellName>/applications/isclite.ear/deployments/isclite/isclite.war/WEB-INF/web.xml: --- Change: < security-constraint> <web-resource-collection> <web-resource-name>Protected Area</web-resource-name> <url-pattern>/</url-pattern> --- So it becomes: < security-constraint> <web-resource-collection> <web-resource-name>Protected Area</web-resource-name> <url-pattern>/</url-pattern> <url-pattern>/logon.jsp</url-pattern> <url-pattern>/logonError.jsp</url-pattern> --- Add these security constraints if not already present: <security-constraint> <web-resource-collection> <web-resource-name>free pages</web-resource-name> <url-pattern>/*.jsp</url-pattern> <url-pattern>/css/*</url-pattern> <url-pattern>/images/*</url-pattern> <url-pattern>/j_security_check</url-pattern> </web-resource-collection> </security-constraint> --- Change: <auth-method>FORM</auth-method> to <auth-method>CLIENT-CERT</auth-method> Save the "web.xml" file. Stop and restart the Deployment Manager. Log on to the admin console using your certificate.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WBSP-AS-001080
- Vuln IDs
-
- V-255866
- V-81325
- Rule IDs
-
- SV-255866r960993_rule
- SV-96039
Checks: C-59539r876887_chk
Review System Security Plan documentation. Interview the system administrator. Identify any application web service providers and the secure authentication requirements for each service provider. From admin console, navigate to Applications >> All applications. Click on each application that is a web service provider where the security plan specifies security extensions are to be applied. Navigate to "Service provider policy sets and bindings". Verify that any web service providers that are required to have security extensions applied as per the security plan have a policy attached. If "Attached policy set" column displays none, but the System Security Plan specifies security extensions as required, this is a finding.
Fix: F-59482r876888_fix
To attach policy sets for your service providers: From admin console, navigate to Applications >> All applications >> [application]. For each application that is a web service provider and requires secure authentication, click on "Service provider policy sets and bindings." Click button on the "Select" column to select a resource. Click on "Attach Policy Set" drop down. Select policy set that best matches the provider environment. Click button on the "Select" column to select the same resource. Click on the "Assign binding" drop down. Select a binding that best matches the environment. Click "Save". Restart DMGR and resync the JVMs.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WBSP-AS-001090
- Vuln IDs
-
- V-255867
- V-81329
- Rule IDs
-
- SV-255867r960993_rule
- SV-96043
Checks: C-59540r876890_chk
Review System Security Plan documentation. Interview the system administrator. Identify any application web service clients. Identify the secure authentication requirements for each client. From admin console, navigate to Applications >> All applications. Click on each application that is a web service client where the security plan specifies security extensions are to be applied. Navigate to "Service client policy sets and bindings". Verify that any web service clients that are required to have security extensions applied as per the security plan have a policy attached. If "Attached policy set" column displays none, but the System Security Plan specifies security extensions as required, this is a finding.
Fix: F-59483r876891_fix
To attach policy sets for your service clients: From admin console, navigate to Applications >> All applications >> [application]. For each application that is a web service client and requires secure authentication, click on "Service client policy sets and bindings." Click button on the "Select" column to select a resource. Click on "Attach Client Policy Set" drop down. Select policy set that best matches the environment. Click button on the "Select" column to select the same resource. Click on the "Assign binding" drop down. Select a binding that best matches the environment. Click "Save". Restart DMGR and resync the JVMs.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- WBSP-AS-001110
- Vuln IDs
-
- V-255868
- V-81333
- Rule IDs
-
- SV-255868r961863_rule
- SV-96047
Checks: C-59541r876893_chk
Review System Security Plan documentation. Identify mutual authentication connection requirements. From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. Select each [NodeDefaultSSLSettings] then go to Quality of Protection (QoP) Settings. If "Client authentication" is not set according to the security plan, this is a finding.
Fix: F-59484r876894_fix
From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. For each [NodeDefaultSSLSettings] select Quality of Protection (QoP) Settings. Set "Client authentication" according to the security plan.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- WBSP-AS-001120
- Vuln IDs
-
- V-255869
- V-81341
- Rule IDs
-
- SV-255869r961863_rule
- SV-96055
Checks: C-59542r876896_chk
Review System Security Plan documentation. Identify mutual authentication connection requirements. From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. Select each [NodeDefaultSSLSettings] then go to Quality of Protection (QoP) Settings. If "Client authentication" is not set according to the security plan, this is a finding. Note: with LDAP registry, the entire DN in the certificate is used to look up LDAP. Filters may be configured. With other registries, only the first attribute after the first "=", e.g., CN=<user> is used.
Fix: F-59485r876897_fix
From the admin console, navigate to Security >> SSL Certificate and Key Management >> SSL Configuration. For each [NodeDefaultSSLSettings] select Quality of Protection (QoP) Settings. Set "Client authentication" according to the security plan.
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000197
- Version
- WBSP-AS-001180
- Vuln IDs
-
- V-255870
- V-81343
- Rule IDs
-
- SV-255870r961029_rule
- SV-96057
Checks: C-59543r876899_chk
Review System Security Plan documentation. Identify any publicly available applications. These are applications available to the public that do not require authentication to access (e.g., recruiting websites). If such applications exist on the system and are specifically allowed according to the security plan, this requirement is NA for those applications only. Navigate to security >> security domains. Click through each security domain. If "Customize for this domain" is checked for Application Security under the Security Attributes, but "Enable application security" is not checked, this is a finding.
Fix: F-59486r876900_fix
Navigate to security >> security domains. Click through each security domain. If "Customize for this domain" is checked for Application Security under the Security Attributes, but "Enable application security" is not checked, check "Enable application security". Expand "show" to find all affected nodes and servers. Click "OK". Click "Save". Synchronize the changes. Restart all affected nodes and servers.
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000197
- Version
- WBSP-AS-001200
- Vuln IDs
-
- V-255871
- V-81347
- Rule IDs
-
- SV-255871r961029_rule
- SV-96061
Checks: C-59544r876902_chk
In the administrative console, click Security >> Global security. Under "User account repository", click "Configure" for the "Standalone LDAP registry", on "Standalone LDAP registry" panel. If the "SSL" flag is not enabled, this is a finding.
Fix: F-59487r876903_fix
In the administrative console, click Security >> Global security. Under User account repository, click the "Available realm definitions" drop-down list. Select Standalone LDAP registry. Click "Configure". Click "SSL enabled". Click "OK". On Global security panel, click "Set as current". Click "Apply". Click "Save". To ensure an error-free operation for this step, you need to first extract to a file the Signer certificate of the LDAP and send that file to the WebSphere Application Server machine. You can then add the certificate to the trust store being defined for the LDAP. In this way, you are assured that the remaining actions for this step will be successful.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-002007
- Version
- WBSP-AS-001210
- Vuln IDs
-
- V-255872
- V-81351
- Rule IDs
-
- SV-255872r961521_rule
- SV-96065
Checks: C-59545r876905_chk
Review System Security Plan documentation. Identify the cache timeout parameters for authentication. Standard value for admin timeout is 10 minutes; however, the ISSO may allow a case by case exception based on operational requirements. From the admin console, navigate to Security >> Global Security >> Authentication cache settings. If "Enable authentication cache" check box is set and "Cache timeout" is larger than the parameters specified in the security plan, this is a finding.
Fix: F-59488r876906_fix
From the admin console, navigate to Security >> Global Security >> Authentication. Click on "Authentication cache" settings. Enter the settings for "Cache timeout" in accordance with the parameters defined in the Systems Security Plan.
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000186
- Version
- WBSP-AS-001230
- Vuln IDs
-
- V-255873
- V-81357
- Rule IDs
-
- SV-255873r961041_rule
- SV-96071
Checks: C-59546r876908_chk
Review System Security Plan documentation. Interview the system administrator. Identify installation folders and DMGR info. Access the DMGR system via the OS. Stop the DMGR processes. This will shut down the application server so plan outages accordingly. The default file paths and DefaultMgr installation names are provided below, adjust paths, and dmgr name if your installation differs from the default. For UNIX systems: cd /opt/IBM/Websphere/Profiles/<DefaultDmgr01>/logs/dmgr/ -stopManager.sh -user [admin user name] - password [admin user password] -archive the SystemOut*.log files. (Copy to another location) -startManager.sh -grep -i cwpki0041w SystemOut.log For Windows: cd C:\program files\IBM\Websphere\Profiles\<DefaultDmgr01>\logs\dmgr\ -stopManager.exe -user [admin user name] - password [admin user password] -archive the SystemOut*.log files. (Copy to another location) -startManager.exe -findstr -I cwpki0041w systemout.log If the results include: "CWPKI0041W: One or more keystores are using the default password", this is a finding.
Fix: F-59489r876909_fix
Navigate to Security >> SSL Certificate and Key Management >> Key stores and certificates. Select a keystore from the list. Click "Change Password". Enter the new password and password confirmation. Click "OK". Repeat for every keystore in the list. Synchronize changes to all nodes.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- WBSP-AS-001260
- Vuln IDs
-
- V-255874
- V-81361
- Rule IDs
-
- SV-255874r961044_rule
- SV-96075
Checks: C-59547r876911_chk
Navigate to Security >> SSl certificate and key management >> SSL Configurations >> CellDefaultSSLSettings >> KeyStores and certificates. Click on cell default trust store. Click on "Signer Certificates". If no DoD root or intermediate certificates are present, this is a finding.
Fix: F-59490r876912_fix
Obtain the signer certificate either as Base 64 encoded ASCII file, or as binary DER data. Navigate to Security >> SSl certificate and key management >> SSL Configurations >> CellDefaultSSLSettings >> key stores and certificates. Click on cell default trust store. Click on "Signer Certificates". Click "Add". Enter a new alias for the signer, and the location of the file that stores signer certificate. For "Data type", choose the type appropriate for the file, either Base64-encoded ASCII data file, or binary DER data. Click "OK".
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- WBSP-AS-001290
- Vuln IDs
-
- V-255875
- V-81365
- Rule IDs
-
- SV-255875r1193273_rule
- SV-96079
Checks: C-59548r1192771_chk
Note: If FIPS 140-3 is configured in WBSP-AS-001770, this is not applicable. From the administrative console, click Security >> SSL certificate and key management >> Manage FIPS. If "Enable FIPS 140-2" is not selected, this is a finding.
Fix: F-59491r876915_fix
From administrative console, click Security >> SSL certificate and key management >> Manage FIPS. Check "Enable FIPS 140-2". Click "Save". Synchronize with the nodes. Restart all the JVMs.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-002009
- Version
- WBSP-AS-001300
- Vuln IDs
-
- V-255876
- V-81367
- Rule IDs
-
- SV-255876r961527_rule
- SV-96081
Checks: C-59549r876917_chk
Check that the admin console is enabled for client certificate logon. In the Deployment Manager, check the file on: <WAS_INSTALL>/profiles/<profileName>/config/cells/<cellName>/applications/isclite.ear/deployments/isclite/isclite.war/WEB-INF/web.xml. If the XML element "<auth-method>FORM</auth-method>" is present, this is a finding.
Fix: F-59492r876918_fix
From the admin console, select System Administration >> Deployment Manager >> Java and Process Management >> Process definition >> Java Virtual Machine >> Custom Properties. Select "New". Insert the following case sensitive value into the "Name" field: "adminconsole.certLogin" Select "Value". Enter "true". Click "Apply". Click "Save". Select Security >> SSL Certificate and Key management >> SSL Configurations >> Select CellDefaultSSLSettings >> Quality of Protection (QOP) settings. In the "Client Authentication" drop box, make sure "Supported" or "Required" is selected. Click "Apply". Click "Save". Save a backup copy and edit the Web.xml file as follows: <WAS_INSTALL>/profiles/<profileName>/config/cells/<cellName>/applications/isclite.ear/deployments/isclite/isclite.war/WEB-INF/web.xml: --- Change: < security-constraint> <web-resource-collection> <web-resource-name>Protected Area</web-resource-name> <url-pattern>/</url-pattern> --- So it becomes: < security-constraint> <web-resource-collection> <web-resource-name>Protected Area</web-resource-name> <url-pattern>/</url-pattern> <url-pattern>/logon.jsp</url-pattern> <url-pattern>/logonError.jsp</url-pattern> --- Add these security constraints if not already present: <security-constraint> <web-resource-collection> <web-resource-name>free pages</web-resource-name> <url-pattern>/*.jsp</url-pattern> <url-pattern>/css/*</url-pattern> <url-pattern>/images/*</url-pattern> <url-pattern>/j_security_check</url-pattern> </web-resource-collection> </security-constraint> --- Change: <auth-method>FORM</auth-method> to <auth-method>CLIENT-CERT</auth-method> Save the "web.xml" file. Stop and restart the Deployment Manager. Log on to the admin console using your certificate.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- WBSP-AS-001370
- Vuln IDs
-
- V-255877
- V-81369
- Rule IDs
-
- SV-255877r1137585_rule
- SV-96083
Checks: C-59550r876920_chk
From administrative console, navigate to Security >> SSL Certificates and Key Management >> KeyStores and Certificates. For each keystore, click on "Signer Certificates". If any of the certificates are not issued by an approved DoD CA, this is a finding.
Fix: F-59493r876921_fix
Utilize DoD certificates that have been issued by a DoD PKI CA. To replace a non-DoD PKI-established certificate: From the administrative console, navigate to Security >> SSL Certificates and Key Management >> KeyStores and Certificates. For each keystore that requires the change: Import a new certificate by clicking "Import". Click "keystore" file. Enter the location of the new certificate. Specify the type of keystore and keystore password. Specify alias information. Click "Apply". After the certificate is imported, click on "Replace" to replace the original certificate with the new certificate.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- WBSP-AS-001390
- Vuln IDs
-
- V-255878
- V-81371
- Rule IDs
-
- SV-255878r1137579_rule
- SV-96085
Checks: C-59551r876923_chk
Review System Security Plan and system architecture documentation. Interview the system administrator. Identify any DMZ networks. If there are no DMZ networks in the application server's architecture, this requirement is NA. In the administrative console, click Servers >> Server Types >> WebSphere application servers. For each application server, review the "hostname" field and determine if the application server has a DMZ network IP address. If any application server is hosted in the DMZ network, this is a finding.
Fix: F-59494r876924_fix
If any application server host is installed in the DMZ, reassign IP address to a secured network and reconfigure the application server.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001184
- Version
- WBSP-AS-001410
- Vuln IDs
-
- V-255879
- V-81373
- Rule IDs
-
- SV-255879r1043178_rule
- SV-96087
Checks: C-59552r876926_chk
Review System Security Plan documentation for location of the trust store used to store the signers of the administrators certificates. By default this is "cellDefaultTrustStore". Navigate to Security >> SSL certificate and key management >> Keystore and certificates. Click on the trust store used to store the signers of the administrators' certificates (root CA). (The default is cellDefaultTrustStore). Click on "Signer Certificates". If there are no DoD signer certificates, this is a finding.
Fix: F-59495r876927_fix
Navigate to Security >> SSL certificate and key management >> Keystore and certificates. Click on the trust store used to store the signers of the administrators' certificates. (The default is cellDefaultTrustStore). Click on "Signer Certificates". Click "Add". Follow the instructions to import the signer from a file. Click "OK".
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- WBSP-AS-001460
- Vuln IDs
-
- V-255880
- V-81375
- Rule IDs
-
- SV-255880r961596_rule
- SV-96089
Checks: C-59553r876929_chk
Review System Security Plan documentation for a list of DoD-approved CAs. From administrative console, navigate to Security >> SSL Certificates and Key Management >> KeyStores and Certificates. For each keystore, click on "Personal Certificates". If any of the certificates are not issued by an approved DoD CA, this is a finding.
Fix: F-59496r876930_fix
Utilize DoD certificates that have been issued by an approved DoD PKI CA. To replace a non-DoD PKI-established certificate: From the administrative console, navigate to Security >> SSL Certificates and Key Management >> KeyStores and Certificates. For each keystores that requires the change: Import a new certificate by clicking "Import". Click "keystore" file. Enter the location of the new certificate. Specify the type of keystore and keystore password. Specify alias information. Click "Apply". After the certificate is imported, click on "Replace" to replace the original certificate with the new certificate.
- RMF Control
- SC-24
- Severity
- L
- CCI
- CCI-001190
- Version
- WBSP-AS-001470
- Vuln IDs
-
- V-255881
- V-81377
- Rule IDs
-
- SV-255881r961122_rule
- SV-96091
Checks: C-59554r876932_chk
Review System Security Plan documentation to determine if the server is configured to use A/B clusters. If the System Security Plan does not specify utilizing A/B clusters, the requirement is NA. From the administration console, select WebSphere application server clusters. Select each cluster name. Select cluster members. If the weight of any cluster member is "0", this is a finding.
Fix: F-59497r876933_fix
From the administration console, select WebSphere application server clusters. Select each cluster name. Select cluster members >> Details. Set all cluster members configured weight to a non-zero value.
- RMF Control
- SC-24
- Severity
- L
- CCI
- CCI-001190
- Version
- WBSP-AS-001480
- Vuln IDs
-
- V-255882
- V-81379
- Rule IDs
-
- SV-255882r961122_rule
- SV-96093
Checks: C-59555r876935_chk
Review Systems Security Plan and identify system categorization. If the system is not categorized as HIGH, this requirement is NA. In the administrative console, click Servers >> Clusters >> WebSphere application server clusters. Ensure you have a cluster defined, if not this is a finding.
Fix: F-59498r876936_fix
In the administrative console, click Servers >> Clusters >> WebSphere application server clusters >> New. Specify a name for the cluster. Click "Next". Specify the name of the first cluster member. Select the node on which you want this cluster member to reside, leave remaining fields as default. Click "Next". Create additional cluster members as needed (give unique name for each member and click "Add Member"), when finished adding members click "Next". Click "Finish" to create the cluster. Click "Save". Refer to vendor documentation that provides direction on the creation of clusters for specific details. Restart DMGR and sync all JVMs.
- RMF Control
- SC-28
- Severity
- L
- CCI
- CCI-002475
- Version
- WBSP-AS-001520
- Vuln IDs
-
- V-255883
- V-81381
- Rule IDs
-
- SV-255883r1067567_rule
- SV-96095
Checks: C-59556r876938_chk
If LTPA is not utilized, this is not applicable. Request the documented process to manually regenerate the LTPA keys. The time period for regeneration must be defined, documented, and accepted by the ISSO but must be performed at least annually. Navigate to Security >> SSL Certificate and Key Management >> Key set groups >> Cell LTPAKeySetGroup. If automatically generate keys is checked, this is a finding.
Fix: F-59499r876939_fix
Navigate to Security >> SSL Certificate and Key Management >> Key set groups >> Cell LTPAKeySetGroup. Uncheck automatically generate keys. Click "OK". Click "Save". Restart the "Deployment Manager".
- RMF Control
- SC-28
- Severity
- L
- CCI
- CCI-002475
- Version
- WBSP-AS-001530
- Vuln IDs
-
- V-255884
- V-81383
- Rule IDs
-
- SV-255884r1067567_rule
- SV-96097
Checks: C-59557r876941_chk
If LTPA is not utilized, this is not applicable. Request the documented process to manually regenerate the LTPA keys. The time period for regeneration must be defined, documented and accepted by the ISSO but must be performed at least annually. Review documented process for LTPA key regeneration. If there is no process to regenerate LTPA keys periodically, this is a finding.
Fix: F-59500r876942_fix
These steps must be documented and then executed during the down time scheduled for periodic LTPA key regeneration. The time period must be defined, documented and accepted by the ISSO but must be performed at least annually. Navigate to Security >> SSL Certificate and Key Management >> Key set groups. Check "CellLTPAKeySetGroup". Click "Generate Keys". Click "Save". Then synchronize the changes to all nodes.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- WBSP-AS-001570
- Vuln IDs
-
- V-255885
- V-81385
- Rule IDs
-
- SV-255885r961620_rule
- SV-96099
Checks: C-59558r876944_chk
Review Systems Security Plan and identify system categorization. If the system is not categorized as HIGH, this requirement is NA. Identify HA applications installed on the server. Verify applications defined as requiring HA protections are running on a cluster. From the admin console, navigate to Application >> All Applications >> [application name] >> Target specific application status. If the target application has been designated as an HA application but is not running on a cluster, this is a finding.
Fix: F-59501r876945_fix
To create a cluster, navigate to Servers >> Clusters >> WebSphere Application Server Clusters >> New and follow the wizard. After cluster creation, re-install your application to the cluster. Refer to product documentation for specific details on how to create and manage WebSphere clusters.
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WBSP-AS-001580
- Vuln IDs
-
- V-255886
- V-81387
- Rule IDs
-
- SV-255886r961620_rule
- SV-96101
Checks: C-59559r876947_chk
Review System Security Plan documentation. Identify the application load requirements defined by system owner. Regular application user session timeout values are defined at the DoD level at 20 minutes. An ISSO risk acceptance is required to deviate from that value. If session timeout values are not set to "20" and an ISSO risk acceptance is provided, this is not a finding. From the admin console, navigate to Servers >> all servers >> [web application server] >> Session management. For every [web application server], verify maximum in-memory session count. Verify "allow overflow" and "session timeout" are set according to application load requirements. If they are not set according to application load requirements, this is a finding.
Fix: F-59502r876948_fix
From the admin console navigate to Servers >> all servers >> [web application server] >> Session management. For every [web application server], set the "Maximum in-memory session count", "allow overflow", and "session timeout" values according to your organizational requirements.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- WBSP-AS-001590
- Vuln IDs
-
- V-255887
- V-81389
- Rule IDs
-
- SV-255887r961620_rule
- SV-96103
Checks: C-59560r876950_chk
Review System Security Plan documentation. Identify the application thread pool size requirements defined by system owner. From the admin console navigate to Servers >> all servers >> [server name] >> ThreadPools. Verify thread pool size according to specifications in documentation. If the maximum size for each threadpool is set too large, and not set according to application requirements, this is a finding.
Fix: F-59503r876951_fix
Perform loading for your application to determine the required thread pool sizes. To set thread pool size: From the admin console >> Servers >> all servers >> [server name] >> Additional Properties >> Select Thread Pools. Set the thread pool size for each threadpool.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WBSP-AS-001610
- Vuln IDs
-
- V-255888
- V-81391
- Rule IDs
-
- SV-255888r961632_rule
- SV-96105
Checks: C-59561r876953_chk
From the administrative console, navigate to Security >> SSL certificate and key management >> SSL configurations >> [Name] >> for each SSL Configuration Select "Quality of protection (QoP) settings". Under "Cipher suite" settings, if any of the ciphers contained in the "Selected ciphers" box" contain "EXPORT" in their name, this is a finding.
Fix: F-59504r876954_fix
From the administrative console, navigate to Security >> SSL certificate and key management >> SSL configurations >> [Name] >> for each SSL configuration Select "Quality of protection (QoP) settings" under "Cipher suite" settings. Identify any ciphers that include "EXPORT" in their name. Remove the cipher by selecting the cipher. Click "Remove" button. Click "OK". Recycle the DMGR and sync the JVMs.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002420
- Version
- WBSP-AS-001620
- Vuln IDs
-
- V-255889
- V-81393
- Rule IDs
-
- SV-255889r961863_rule
- SV-96107
Checks: C-59562r876956_chk
From the admin console navigate to Servers >> Core groups. For every Core Group listed, select the Core Group [CoreGroup Name]. Under "Transport Type", select the "Channel Framework" button. If the "transport chain" drop down box is not set to "DCS-Secure", this is a finding.
Fix: F-59505r876957_fix
From the admin console navigate to Core groups >> for every Core Group listed. Select the [Core Group Name]. Under "Transport" type, select "CHANNEL_FRAMEWORK" button. In the "Transport chain" drop down box set to "DCS-SECURE". Click "Save". Sync the configuration.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002421
- Version
- WBSP-AS-001630
- Vuln IDs
-
- V-255890
- V-81395
- Rule IDs
-
- SV-255890r1137581_rule
- SV-96109
Checks: C-59563r876959_chk
From the admin console, navigate to Servers >> Server Types >> WebSphere Application Servers >> select each server (server name) >> Web Container Settings >> Web container transport chains. Verify both "WCInboundDefault" and the "HttpQueueInboundDefault" transport chains are disabled. If they are not disabled, this is a finding.
Fix: F-59506r876960_fix
From the admin console, navigate to Servers >> Server Types >> WebSphere Application Servers >> select each server (server name) >> Web Container Settings >> Web container transport chains. Select the "WCInboundDefault" and the "HttpQueueInboundDefault" transport chains and disable them. Click "Apply". Click "Save". Restart the DMGR and resynch the JVMs.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002617
- Version
- WBSP-AS-001740
- Vuln IDs
-
- V-255891
- V-81397
- Rule IDs
-
- SV-255891r961677_rule
- SV-96111
Checks: C-59564r876962_chk
Review System Security Plan and system documentation to locate the "IBM InstallationManager" folder. Default locations are: UNIX: /opt/InstallationManager Windows: C:\Program Files\InstallationManager UNIX: <IMHOME>/eclipse/tools/imcl -c Select "P" preferences. Select "3" Files for rollback. Windows: <IMHOME>\eclipse\tools\imcl.exe -c Select "P" preferences. Select "3" Files for rollback. If "Save files for rollback" is checked, this is a finding.
Fix: F-59507r876963_fix
Review System Security Plan and system documentation to locate the "IBM InstallationManager" folder. Default locations are: UNIX: /opt/InstallationManager Windows: C:\Program Files\InstallationManager UNIX: <IMHOME>/eclipse/tools/imcl -c Select "P" preferences. Select "3" Files for rollback. Enter "1" to deselect. Enter "A" for apply. Enter "R" to return to Main Menu. Windows: <IMHOME>\eclipse\tools\imcl.exe -c Select "P" preferences. Select "3" Files for rollback. Enter "1" to deselect. Enter "A" for apply. Enter "R" to return to Main Menu.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- WBSP-AS-001750
- Vuln IDs
-
- V-255892
- V-81399
- Rule IDs
-
- SV-255892r1137612_rule
- SV-96113
Checks: C-59565r876965_chk
Use the admin console to determine the WebSphere version. Review patch level and fix pack. If the most recent patches/fix packs have not been applied, this is a finding.
Fix: F-59508r876966_fix
Obtain WebSphere product security and patch support. Test and apply the latest applicable WebSphere security fixes.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- WBSP-AS-001760
- Vuln IDs
-
- V-255893
- V-81401
- Rule IDs
-
- SV-255893r1137612_rule
- SV-96115
Checks: C-59566r876968_chk
From the admin console, click on "welcome". Under Suite Name, locate "WebSphere Application Server". View the "version". Access IBM support website: https://www.ibm.com/support Identify the most recent patch/fix version available for the WebSphere Traditional Application Server (not the Liberty version). If the most recent patches/fix packs have not been applied, this is a finding.
Fix: F-59509r876969_fix
Sign up to receive WebSphere security bulletins at the IBM website. Monitor IAVMs, CTOs, and DTMs for update notices affecting WebSphere. Obtain WebSphere product security and patch support. Test and apply the latest applicable WebSphere security fixes.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- WBSP-AS-001770
- Vuln IDs
-
- V-283677
- Rule IDs
-
- SV-283677r1193276_rule
Checks: C-88242r1193274_chk
Note: If FIPS 140-2 is configured in WBSP-AS-001290, this is not applicable. This is allowed until 21 September 2026. If FIPS 140-2 is still in use after this date, this is a finding. From administrative console, click Security >> SSL certificate and key management >> Manage FIPS. If "Enable FIPS 140-3" is not selected, this is a finding.
Fix: F-88147r1193275_fix
Implementation for Cell Profile (Network Deployment): 1. Back up the existing configuration: backupConfig.sh <backup_directory> 2. Stop all servers except the deployment manager: - Stop all node agents and application servers. - Keep only the deployment manager running. 3. Enable FIPS 140-3. Option A - Using Administrative Console: 1. Click Security >> SSL certificate and key management >> Manage FIPS. 2. Select "Enable FIPS 140-3". 3. Click "Apply". Option B - Using Admin Command: AdminTask.enableFips('[-enableFips true -fipsLevel FIPS140-3 ]') 1. Stop the deployment manager. 2. Restart the deployment manager. 3. Synchronize nodes. On each node, run: syncNode.sh <dmgr_host> <dmgr_port> 4. Start node agents and servers Implementation for Standalone Profile: 1. Back up the existing configuration: backupConfig.sh <backup_directory> 2. Enable FIPS 140-3. Option A - Using Administrative Console: 1. Click Security >> SSL certificate and key management >> Manage FIPS. 2. Select "Enable FIPS 140-3". 3. Click "Apply". Option B - Using Admin Command: AdminTask.enableFips('[-enableFips true -fipsLevel FIPS140-3 ]') For both methods, restart the application server.