Web Server Security Requirements Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- SRG-APP-000001-WSR-000001
- Vuln IDs
-
- V-40791
- Rule IDs
-
- SV-53018r1_rule
Checks: C-47298r1_chk
Review the web server documentation and configuration to determine if the number of concurrent sessions is limited to an organization-defined number of sessions. If the parameter is not configured, this is a finding.
Fix: F-45918r1_fix
Configure the web server to limit the number of concurrent sessions.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- SRG-APP-000001-WSR-000002
- Vuln IDs
-
- V-40792
- Rule IDs
-
- SV-53023r1_rule
Checks: C-47329r1_chk
Review the web server documentation and configuration to determine if server-side session management is configured. If it is not configured, this is a finding.
Fix: F-45949r1_fix
Configure the web server to perform server-side session management.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000066
- Version
- SRG-APP-000140-WSR-000003
- Vuln IDs
-
- V-40797
- Rule IDs
-
- SV-53032r1_rule
Checks: C-47339r1_chk
Review organization policy, web server product documentation, and deployed configuration to determine if the server is enforcing the organizations requirements for remote connections. If the web server is not configured to enforce these requirements, or the remote connection settings are not in accordance with the requirements, this is a finding.
Fix: F-45959r1_fix
Configure the web server to enforce remote access policy or to work with enterprise tools designed to enforce remote access policy.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000066
- Version
- SRG-APP-000140-WSR-000004
- Vuln IDs
-
- V-40798
- Rule IDs
-
- SV-53034r1_rule
Checks: C-47340r1_chk
Review the web server documentation and configuration to verify if access restrictions are in place from non-secure zone. If not, then this is a finding.
Fix: F-45960r1_fix
Configure the web server to block access from DoD defined non-secure zones.
- RMF Control
- AC-17
- Severity
- L
- CCI
- CCI-000067
- Version
- SRG-APP-000016-WSR-000005
- Vuln IDs
-
- V-40799
- Rule IDs
-
- SV-53035r1_rule
Checks: C-47342r1_chk
Review the web server documentation and configuration to determine if the web server is configured to generate information for external applications monitoring remote access. If a mechanism is not in place providing information to an external application used to monitor and control access, this is a finding.
Fix: F-45961r1_fix
Configure the web server to provide remote connection information to external monitoring and access control applications.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- SRG-APP-000014-WSR-000006
- Vuln IDs
-
- V-40800
- Rule IDs
-
- SV-53037r1_rule
Checks: C-47343r1_chk
Review the web server documentation and configuration to determine the communication methods that are being used. Verify the encryption being used is in accordance with the data being presented or retrieved. If it is not, then this is a finding.
Fix: F-45963r1_fix
Configure the web server to use encryption strength equal to the categorization of the data being hosted.
- RMF Control
- AC-17
- Severity
- L
- CCI
- CCI-000069
- Version
- SRG-APP-000017-WSR-000007
- Vuln IDs
-
- V-40801
- Rule IDs
-
- SV-53038r1_rule
Checks: C-47344r1_chk
Review the web server documentation and configuration to determine if the web server is part of a cluster. If the web server is not part of a cluster, then this is NA. If the web server is part of a cluster and is not centrally managed, then this is a finding.
Fix: F-45964r1_fix
Configure the web server to be centrally managed.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-001399
- Version
- SRG-APP-000006-WSR-000008
- Vuln IDs
-
- V-40806
- Rule IDs
-
- SV-53048r1_rule
Checks: C-47354r1_chk
Review the web server documentation and configuration to determine where server content and scripts are located. Verify the users who can change these files are privileged users. If users other than privileged users may change server content and scripts, this is a finding.
Fix: F-45974r1_fix
Configure the web server to protect the server content and scripts from changes made by non-privileged users.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-001399
- Version
- SRG-APP-000006-WSR-000009
- Vuln IDs
-
- V-40807
- Rule IDs
-
- SV-53049r1_rule
Checks: C-47355r1_chk
Review the web server documentation and configuration to determine which files are web server system files. Verify these files have the minimum permission needed for operation of the web server. If the files do not conform to minimum permissions, this is a finding.
Fix: F-45975r1_fix
Configure the web server system files with minimum privileges required for web server operation.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-001399
- Version
- SRG-APP-000006-WSR-000010
- Vuln IDs
-
- V-40808
- Rule IDs
-
- SV-53051r1_rule
Checks: C-47357r1_chk
Review the web server documentation and configuration to determine if any user identifiers and passwords are being stored by the web server for application authorization. If user credentials are not being stored, the finding is NA. If user credentials are being stored, verify the files have minimum privileges required for operation. If the files do not conform to minimum permissions, this is a finding.
Fix: F-45977r1_fix
Configure the web server files containing user identifiers and passwords with the minimum privileges required for web server operation.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-001399
- Version
- SRG-APP-000006-WSR-000011
- Vuln IDs
-
- V-40809
- Rule IDs
-
- SV-53052r1_rule
Checks: C-47358r1_chk
Review the web server documentation and configuration to determine if cookies between the web server and client are accessible by applications or web servers other than the originating pair. If the cookie information is accessible outside the originating pair, this is a finding.
Fix: F-45978r1_fix
Configure the web server to set properties within cookies to disallow the cookie to be accessed by other web servers and applications.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-001399
- Version
- SRG-APP-000006-WSR-000012
- Vuln IDs
-
- V-40810
- Rule IDs
-
- SV-53053r1_rule
Checks: C-47360r1_chk
Review the web server documentation and configuration to determine if cookies are being expired. If cookies have no expiration date, this is a finding.
Fix: F-45979r1_fix
Configure the web server to set expiration dates on cookies exchanged between the web server and the client.
- RMF Control
- AC-17
- Severity
- L
- CCI
- CCI-001436
- Version
- SRG-APP-000020-WSR-000013
- Vuln IDs
-
- V-40818
- Rule IDs
-
- SV-53067r1_rule
Checks: C-47373r1_chk
Review the web server documentation to determine if HTTP and HTTPS are used in accordance with the Internet Assigned Numbers Authority (IANA) well known ports (e.g., 80 and 443) or those ports and services as registered and approved for use by the DoD PPSM. If HTTP and HTTPS are not being used in accordance with IANA, this is a finding.
Fix: F-45993r1_fix
Ensure the website enforces the use of IANA well-known ports for HTTP and HTTPS.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- SRG-APP-000015-WSR-000014
- Vuln IDs
-
- V-40819
- Rule IDs
-
- SV-53068r1_rule
Checks: C-47375r1_chk
Review the web server documentation and configuration to ensure the web server is configured to use cryptography to protect the integrity of remote access sessions. If the web server is not configured to use cryptography to protect the integrity of remote access sessions, this is a finding.
Fix: F-45994r1_fix
Configure the web server to utilize encryption during remote access sessions.
- RMF Control
- AC-2
- Severity
- L
- CCI
- CCI-000015
- Version
- SRG-APP-000023-WSR-000015
- Vuln IDs
-
- V-40821
- Rule IDs
-
- SV-53071r1_rule
Checks: C-47377r1_chk
Review the web server documentation and configuration to see if the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must offer an automated facility to manage user accounts. If there is no automated facility to manage user accounts, this is a finding.
Fix: F-45997r1_fix
Configure the web server to use an automated mechanism for user management.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000016
- Version
- SRG-APP-000024-WSR-000016
- Vuln IDs
-
- V-40822
- Rule IDs
-
- SV-53073r1_rule
Checks: C-47379r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management for the hosted application, the web server must automatically terminate accounts designated as temporary after a defined amount of time. If the web server does not automatically terminate temporary user accounts after a defined time period, this is a finding.
Fix: F-45999r1_fix
Configure the web server to automatically terminate accounts designated as temporary after a defined amount of time.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000017
- Version
- SRG-APP-000025-WSR-000017
- Vuln IDs
-
- V-40823
- Rule IDs
-
- SV-53074r1_rule
Checks: C-47380r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must have an automated mechanism to disable accounts that are inactive for 35 days or more. If the web server does not have a facility to monitor accounts and disable them after inactivity, this is a finding.
Fix: F-46000r1_fix
Configure the web server to use an automated mechanism to disable inactive accounts after a 35-day period of inactivity.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- SRG-APP-000026-WSR-000018
- Vuln IDs
-
- V-40824
- Rule IDs
-
- SV-53075r1_rule
Checks: C-47381r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must automatically log the creation of user accounts. If the web server does not automatically log account creation, this is a finding.
Fix: F-46001r1_fix
Configure the web server to automatically log the creation of user accounts.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001356
- Version
- SRG-APP-000030-WSR-000019
- Vuln IDs
-
- V-40827
- Rule IDs
-
- SV-53078r1_rule
Checks: C-47384r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must log account usage and provide the logged events to an enterprise tool used to discover account atypical use. If the web server does not log event usage or provide logs to an enterprise tool that monitors for atypical account usage, this is a finding.
Fix: F-46004r1_fix
Configure the web server to log account usage in a standardized format and forward to an enterprise tool for atypical account usage evaluation.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001403
- Version
- SRG-APP-000027-WSR-000020
- Vuln IDs
-
- V-40828
- Rule IDs
-
- SV-53079r1_rule
Checks: C-47385r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must log account modification and provide the logged event. If the web server does not log account modification, this is a finding.
Fix: F-46005r1_fix
Configure the web server to automatically log the modification of user accounts.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001404
- Version
- SRG-APP-000028-WSR-000021
- Vuln IDs
-
- V-40829
- Rule IDs
-
- SV-53080r1_rule
Checks: C-47386r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must log events that disable user accounts and notify appropriate individuals. If the web server does not log an account being disabled and notify appropriate individuals, this is a finding.
Fix: F-46006r1_fix
Configure the web server to automatically log the disabling of user accounts and to notify appropriate individuals.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001405
- Version
- SRG-APP-000029-WSR-000022
- Vuln IDs
-
- V-40830
- Rule IDs
-
- SV-53082r1_rule
Checks: C-47388r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must log events that terminate user accounts and notify appropriate individuals. If the web server does not log account termination and notify appropriate individuals, this is a finding.
Fix: F-46008r1_fix
Configure the web server to automatically log the termination of user accounts and notify appropriate individuals.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001682
- Version
- SRG-APP-000234-WSR-000023
- Vuln IDs
-
- V-40831
- Rule IDs
-
- SV-53083r1_rule
Checks: C-47389r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management for the hosted application, the web server must automatically terminate accounts designated as emergency accounts after a defined amount of time. If the web server does not automatically terminate emergency user accounts, this is a finding.
Fix: F-46009r1_fix
Configure the web server to automatically terminate accounts designated as emergency accounts.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001683
- Version
- SRG-APP-000291-WSR-000024
- Vuln IDs
-
- V-40832
- Rule IDs
-
- SV-53084r1_rule
Checks: C-47390r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must notify appropriate individuals when accounts are created. If the web server does not notify appropriate individuals on account creation, this is a finding.
Fix: F-46010r1_fix
Configure the web server to notify appropriate individuals on account creation.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001684
- Version
- SRG-APP-000292-WSR-000025
- Vuln IDs
-
- V-40833
- Rule IDs
-
- SV-53086r1_rule
Checks: C-47392r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must notify appropriate individuals when accounts are modified. If the web server does not notify appropriate individuals on account modification, this is a finding.
Fix: F-46012r1_fix
Configure the web server to notify appropriate individuals on account modification.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001685
- Version
- SRG-APP-000293-WSR-000026
- Vuln IDs
-
- V-40834
- Rule IDs
-
- SV-53087r1_rule
Checks: C-47393r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must notify appropriate individuals when a user account is disabled. If the web server does not notify appropriate individuals when a user account is disabled, this is a finding.
Fix: F-46013r1_fix
Configure the web server to automatically notify appropriate individuals when user accounts are disabled.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001686
- Version
- SRG-APP-000294-WSR-000027
- Vuln IDs
-
- V-40835
- Rule IDs
-
- SV-53088r1_rule
Checks: C-47394r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted application, the web server must notify appropriate individuals when a user account is terminated. If the web server does not notify appropriate individuals when a user account is terminated, this is a finding.
Fix: F-46014r1_fix
Configure the web server to automatically notify appropriate individuals on the termination of user accounts.
- RMF Control
- AC-5
- Severity
- L
- CCI
- CCI-000037
- Version
- SRG-APP-000062-WSR-000028
- Vuln IDs
-
- V-40873
- Rule IDs
-
- SV-53205r1_rule
Checks: C-47511r1_chk
Review the web server documentation and the deployed configuration to determine the accounts used to accomplish administrative and operational duties for the web server. Verify the accounts are separated by the different roles that are needed to accomplish the administrative and operational tasks. Also, verify the accounts and roles are documented. If separate accounts are not used to perform administrative and operational tasks for the web server and the accounts and roles are not documented, this is a finding.
Fix: F-46131r1_fix
Set up and document accounts and roles that are used to perform defined administrative and operational tasks.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-000040
- Version
- SRG-APP-000063-WSR-000029
- Vuln IDs
-
- V-40874
- Rule IDs
-
- SV-53206r1_rule
Checks: C-47512r1_chk
Review the web server documentation and configuration to determine if accounts used for administrative duties of the web server are separated from non-privileged accounts. If non-privileged accounts can access web server security-relevant information, this is a finding.
Fix: F-46132r1_fix
Set up accounts and roles that can only be used to perform web server security-relevant tasks.
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-000040
- Version
- SRG-APP-000063-WSR-000030
- Vuln IDs
-
- V-40876
- Rule IDs
-
- SV-53208r1_rule
Checks: C-47514r1_chk
Review the web server documentation and configuration to determine what accounts are available on the server hosting the web server. If accounts are available with access to functions, directories, or files not needed for the role of the account, this is a finding.
Fix: F-46134r1_fix
Limit the functions, directories, and files that are accessible by each account and role.
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-000040
- Version
- SRG-APP-000063-WSR-000031
- Vuln IDs
-
- V-40877
- Rule IDs
-
- SV-53209r1_rule
Checks: C-47515r1_chk
Review the web server documentation and configuration to determine if anonymous users can make changes to the web server or any applications hosted by the web server. If anonymous users can make changes, this is a finding.
Fix: F-46135r1_fix
Configure the web server to not allow anonymous users to change the web server or any hosted applications.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- SRG-APP-000065-WSR-000038
- Vuln IDs
-
- V-41588
- Rule IDs
-
- SV-54165r1_rule
Checks: C-48017r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management for the hosted application, the web server must limit the number of failed login attempts during a specified time period by locking or disabling the account. If the web server does not limit the number of failed logins during a defined time period, this is a finding.
Fix: F-47047r1_fix
Configure the web server to limit the number of failed logins during a specified time period.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000047
- Version
- SRG-APP-000067-WSR-000039
- Vuln IDs
-
- V-41589
- Rule IDs
-
- SV-54166r1_rule
Checks: C-48018r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management for the hosted application, the web server must lock or disable an account after a specified number of failed logins. If the web server does not lock or disable an account after a specified number of failed logins, this is a finding.
Fix: F-47048r1_fix
Configure the web server to lock an account after a specified number of failed logins.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-001452
- Version
- SRG-APP-000066-WSR-000040
- Vuln IDs
-
- V-41590
- Rule IDs
-
- SV-54167r1_rule
Checks: C-48019r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management for the hosted application, the web server must enforce a time period during which the number of consecutive invalid access attempts are counted. If the web server does not allow definition of a time period during which the number of consecutive invalid access attempts are counted, this is a finding.
Fix: F-47049r1_fix
Configure the web server to only count failed consecutive access attempts during a defined time period.
- RMF Control
- AC-9
- Severity
- L
- CCI
- CCI-000052
- Version
- SRG-APP-000075-WSR-000041
- Vuln IDs
-
- V-41594
- Rule IDs
-
- SV-54171r1_rule
Checks: C-48023r1_chk
Review the web server documentation and configuration to determine if the web server is also performing hosted application user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management for the hosted application, the web server must record each user's date and time of the last successful logon. If the last successful logon is not recorded, this is a finding.
Fix: F-47053r1_fix
Configure the web server to record the last successful logon date and time for each user.
- RMF Control
- AU-10
- Severity
- L
- CCI
- CCI-000166
- Version
- SRG-APP-000080-WSR-000046
- Vuln IDs
-
- V-41599
- Rule IDs
-
- SV-54176r1_rule
Checks: C-48028r1_chk
Review the web server documentation and configuration to determine if the web server forces the signing of documents, such as configurations, certificates, and hosted application files before the changes are implemented. If the web server cannot enforce the signing of files, determine if some other external tool is used to force the signing of files before becoming part of the production web server. If changes can be made without signing the files, this is a finding.
Fix: F-47058r1_fix
Configure the web server to enforce signing of changes before the changes become part of the running web server configuration.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- SRG-APP-000089-WSR-000047
- Vuln IDs
-
- V-41600
- Rule IDs
-
- SV-54177r1_rule
Checks: C-48029r1_chk
Review the web server documentation and deployed web server configuration to determine if the system generates audit records for definable events. Perform functionality testing and examine log data to ensure defined events are logged. If the system cannot perform this function, this is a finding.
Fix: F-47059r2_fix
Configure the web server to audit at the defined event level.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- SRG-APP-000091-WSR-000048
- Vuln IDs
-
- V-41602
- Rule IDs
-
- SV-54179r1_rule
Checks: C-48031r1_chk
Review the web server documentation and the deployed system configuration to determine if the DoD-required auditable events are recorded. Required events include system startup and shutdown, successful and unsuccessful application deployment attempts, program execution, and integrity validation failures. Verify a reasonable subset of these events is captured in practice by examining the audit logs. If the audit logs do not include DoD-required auditable events, this is a finding.
Fix: F-47061r1_fix
Configure the web server to generate audit records for the DoD-required auditable events.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000174
- Version
- SRG-APP-000086-WSR-000049
- Vuln IDs
-
- V-41603
- Rule IDs
-
- SV-54180r1_rule
Checks: C-48032r1_chk
Review the web server audit feature configuration to determine if the web server can compile audit records from multiple components within the server into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance. If the web server does not meet this requirement, or cannot be configured to utilize an external tool that provides this capability, this is a finding.
Fix: F-47062r1_fix
Configure the web server to compile audit records from multiple components within the server into a system-wide (logical or physical) audit trail that is time correlated or configure the web server to utilize an external auditing tool designed to meet this requirement.
- RMF Control
- AU-14
- Severity
- M
- CCI
- CCI-001462
- Version
- SRG-APP-000093-WSR-000053
- Vuln IDs
-
- V-41609
- Rule IDs
-
- SV-54186r1_rule
Checks: C-48038r1_chk
Review the web server documentation and deployed configuration to determine if the web server captures and logs all content related to a user session. Request a user access the hosted applications and verify the complete session is logged. If any of the session is excluded from the log, this is a finding.
Fix: F-47068r1_fix
Configure the web server to capture and log all content related to a user session.
- RMF Control
- AU-14
- Severity
- L
- CCI
- CCI-001463
- Version
- SRG-APP-000094-WSR-000054
- Vuln IDs
-
- V-41610
- Rule IDs
-
- SV-54187r1_rule
Checks: C-48039r1_chk
Review the web server documentation and deployed configuration to determine if the web server provides a capability to remotely view all content related to an established user session in real time. If the web server does not offer this capability, review the configuration along with the domain topology to determine if an external device is in place to offer this capability. If there is no capability to remotely view all content related to a user's session, this is a finding.
Fix: F-47069r1_fix
Configure the web server to allow the viewing of an established user session in real time. If the web server does not offer this capability, install and configure an external device that will provide the capability to view established user session data in real time.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- SRG-APP-000095-WSR-000056
- Vuln IDs
-
- V-41612
- Rule IDs
-
- SV-54189r1_rule
Checks: C-48041r1_chk
Review the web server documentation and deployed configuration to determine if the web server contains sufficient information to establish what type of event occurred. Request a user access the hosted applications and verify sufficient information is recorded. If sufficient information is not logged, this is a finding.
Fix: F-47071r1_fix
Configure the web server to record more information with each event so that the type of event can be determined.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000131
- Version
- SRG-APP-000096-WSR-000057
- Vuln IDs
-
- V-41613
- Rule IDs
-
- SV-54190r1_rule
Checks: C-48042r1_chk
Review the web server documentation and deployment configuration to determine if the web server is configured to generate a date and time for each audited event. Request a user access the hosted application and generate auditable events and then review the audit logs to determine if the date and time are included in the log event data. If the date and time are not included, this is a finding.
Fix: F-47072r1_fix
Configure the web server to log date and time with the event.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- SRG-APP-000097-WSR-000058
- Vuln IDs
-
- V-41614
- Rule IDs
-
- SV-54191r1_rule
Checks: C-48043r1_chk
Review the web server documentation and deployment configuration to determine if the web server is configured to generate sufficient information to resolve where within the web server the audit event occurred. Request a user access the hosted application and generate auditable events and then review the audit logs to determine if the location within the web server of the event can be established. If it cannot be determined where the event occurred, this is a finding.
Fix: F-47073r1_fix
Configure the web server to generate enough information to determine where within the web server the log event occurred.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000133
- Version
- SRG-APP-000098-WSR-000059
- Vuln IDs
-
- V-41615
- Rule IDs
-
- SV-54192r1_rule
Checks: C-48044r1_chk
Review the web server documentation and deployment configuration to determine if the web server is configured to generate sufficient information to resolve the source of the audit event. Request a user access the hosted application and generate auditable events and then review the audit logs to determine if the source of the event can be established. If the source of the event cannot be determined, this is a finding.
Fix: F-47074r1_fix
Configure the web server to generate the source of each auditable event.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000133
- Version
- SRG-APP-000098-WSR-000060
- Vuln IDs
-
- V-41616
- Rule IDs
-
- SV-54193r1_rule
Checks: C-48045r1_chk
Review the deployment configuration to determine if the web server is sitting behind a proxy server. If the web server is not sitting behind a proxy server, this finding is NA. If the web server is behind a proxy server, review the documentation and deployment configuration to determine if the web server is configured to generate sufficient information to resolve the source of the audit event and not the proxy server. Request a user access the hosted application through the proxy server and generate auditable events and then review the audit logs to determine if the source of the event can be established. If the source of the event cannot be determined, this is a finding.
Fix: F-47075r1_fix
Configure the web server to generate the client source, not the load balancer or proxy server, of each auditable event.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- SRG-APP-000099-WSR-000061
- Vuln IDs
-
- V-41617
- Rule IDs
-
- SV-54194r1_rule
Checks: C-48046r1_chk
Review the web server documentation and deployment configuration to determine if the web server is configured to generate the outcome of the audit event. Request a user access the hosted application and generate auditable events and then review the audit logs to determine if the outcome of the event can be established. If the outcome of the event cannot be determined, this is a finding.
Fix: F-47076r1_fix
Configure the web server to generate the outcome, success or failure, as part of each auditable event.
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000135
- Version
- SRG-APP-000101-WSR-000062
- Vuln IDs
-
- V-41618
- Rule IDs
-
- SV-54195r1_rule
Checks: C-48047r1_chk
Review the web server documentation and deployment configuration to determine if the web server is configured to generate DoD-defined additional information for each auditable event. Request a user access the hosted application and generate auditable events and then review the audit logs to determine if the additional information is generated. If the DoD-defined additional information is not present, this is a finding.
Fix: F-47077r1_fix
Configure the web server to generate the additional DoD-defined information for each auditable event.
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000136
- Version
- SRG-APP-000102-WSR-000063
- Vuln IDs
-
- V-41619
- Rule IDs
-
- SV-54196r1_rule
Checks: C-48048r1_chk
Review the web server documentation and deployment configuration to determine if the web server can write audit data to, or if audit data can be transferred to, a separate audit server. Request a user access the hosted application and generate auditable events and verify the audit data is written to a separate audit server. If audit logs cannot be directly written or transferred on request or on a periodic schedule to an audit log server, this is a finding.
Fix: F-47078r1_fix
Configure the web server to directly write or transfer the audit logs to a remote audit log server.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001487
- Version
- SRG-APP-000100-WSR-000064
- Vuln IDs
-
- V-41620
- Rule IDs
-
- SV-54197r1_rule
Checks: C-48049r1_chk
Review the web server documentation and deployment configuration to determine if the web server can generate audit data containing the user/subject identity. Request a user access the hosted application and generate auditable events and verify the events contain the user/subject or process identity. If the identity is not part of the audit record, this is a finding.
Fix: F-47079r1_fix
Configure the web server to include the user/subject identity as part of each audit record.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000143
- Version
- SRG-APP-000103-WSR-000065
- Vuln IDs
-
- V-41625
- Rule IDs
-
- SV-54202r1_rule
Checks: C-48054r1_chk
Review the web server documentation and deployment configuration settings to determine if the web server audit system provides a warning when allocated audit record storage volume reaches an organization-defined percentage of maximum audit record storage capacity. If designated alerts are not sent or the web server is not configured to use a dedicated audit tool that meets this requirement, this is a finding.
Fix: F-47084r1_fix
Configure the web server to provide a warning when allocated audit record storage volume reaches an organization-defined percentage of maximum audit record storage capacity.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000144
- Version
- SRG-APP-000104-WSR-000166
- Vuln IDs
-
- V-41626
- Rule IDs
-
- SV-54203r1_rule
Checks: C-48055r1_chk
Review the web server documentation and deployment configuration settings to determine if the web server audit system provides a real-time alert when organization-defined audit failures occur. If designated alerts are not sent or the web server is not configured to use a dedicated audit tool that meets this requirement, this is a finding.
Fix: F-47085r1_fix
Configure the web server to provide a real-time alert when organization-defined audit failures occur.
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000159
- Version
- SRG-APP-000116-WSR-000066
- Vuln IDs
-
- V-41668
- Rule IDs
-
- SV-54245r1_rule
Checks: C-48065r1_chk
Review the web server documentation and deployment configuration to determine if the internal system clock is used for date and timestamps. If this is not feasible, an alternative workaround is to take an action that generates an entry in the audit log and then immediately query the operating system for the current time. A reasonable match between the two times will suffice as evidence that the system is using the internal clock for date and timestamps. If the web server does not use the internal system clock to generate timestamps, this is a finding.
Fix: F-47127r1_fix
Configure the web server to use internal system clocks to generate date and timestamps for audit records.
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000160
- Version
- SRG-APP-000117-WSR-000067
- Vuln IDs
-
- V-41669
- Rule IDs
-
- SV-54246r1_rule
Checks: C-48066r1_chk
Review the web server documentation and deployment configuration to determine if the web server defers to the operating system for accurate timekeeping. If the web server provides its own timekeeping service, this is a finding.
Fix: F-47128r1_fix
Configure the web server to utilize the timekeeping services of the host OS.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- SRG-APP-000118-WSR-000068
- Vuln IDs
-
- V-41670
- Rule IDs
-
- SV-54247r1_rule
Checks: C-48067r1_chk
Review the web server documentation and deployed configuration settings to determine if the web server audit features protect audit information from unauthorized access. Review file system settings to verify the log files have secure file permissions. If the web server log files are not protected from unauthorized access, this is a finding.
Fix: F-47129r1_fix
Configure the web server log files so unauthorized access of audit information is not possible.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- SRG-APP-000119-WSR-000069
- Vuln IDs
-
- V-41671
- Rule IDs
-
- SV-54248r1_rule
Checks: C-48068r1_chk
Review the web server documentation and deployed configuration settings to determine if the web server audit features protect audit information from unauthorized modification. Review file system settings to verify the log files have secure file permissions. If the web server log files are not protected from unauthorized modification, this is a finding.
Fix: F-47130r1_fix
Configure the web server log files so unauthorized modification of audit information is not possible.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- SRG-APP-000120-WSR-000070
- Vuln IDs
-
- V-41672
- Rule IDs
-
- SV-54249r1_rule
Checks: C-48069r1_chk
Review the web server documentation and deployed configuration settings to determine if the web server audit features protect audit information from unauthorized deletion. Review file system settings to verify the log files have secure file permissions. If the web server log files are not protected from unauthorized deletion, this is a finding.
Fix: F-47131r1_fix
Configure the web server log files so unauthorized deletion of audit information is not possible.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-000345
- Version
- SRG-APP-000128-WSR-000072
- Vuln IDs
-
- V-41681
- Rule IDs
-
- SV-54258r1_rule
Checks: C-48078r1_chk
Review the web server documentation and configuration to determine if the web server provides unique account roles specifically for the purposes of segmenting the responsibilities for managing the web server. Log into the hosting server using a web server role with limited permissions (e.g., Auditor, Developer, etc.) and verify the account is not able to perform configuration changes that are not related to that role. If roles are not defined with limited permissions and restrictions, this is a finding.
Fix: F-47140r1_fix
Define roles and responsibilities to be used when managing the web server. Configure the hosting system to utilize specific roles that restrict access related to web server system and configuration changes.
- RMF Control
- CM-5
- Severity
- L
- CCI
- CCI-000352
- Version
- SRG-APP-000131-WSR-000073
- Vuln IDs
-
- V-41684
- Rule IDs
-
- SV-54261r1_rule
Checks: C-48081r1_chk
Review the web server documentation and configuration to determine if web server modules are fully tested before implementation in the production environment. Review the web server for modules identified as test, debug, or backup and that cannot be reached through the hosted application. Review the web server to see if the web server or an external utility is in use to enforce the signing of modules before they are put into a production environment. If development and testing is taking place on the production web server or modules are put into production without being signed, this is a finding.
Fix: F-47143r1_fix
Configure the web server to enforce, internally or through an external utility, the signing of modules before implementation into the production environment.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000075
- Vuln IDs
-
- V-41693
- Rule IDs
-
- SV-54270r1_rule
Checks: C-48090r1_chk
Review the web server documentation and deployed configuration to determine if web server features, services, and processes are installed that are not needed for hosted application deployment. If excessive features, services, and processes are installed, this is a finding.
Fix: F-47152r1_fix
Uninstall or deactivate features, services, and processes not needed by the web server for operation.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000076
- Vuln IDs
-
- V-41694
- Rule IDs
-
- SV-54271r1_rule
Checks: C-48091r1_chk
Review the web server documentation and deployed configuration to determine if the web server is also a proxy server. If the web server is also acting as a proxy server, this is a finding.
Fix: F-47153r1_fix
Uninstall any proxy services, modules, and libraries that are used by the web server to act as a proxy server. Verify all configuration changes are made to ensure the web server is no longer acting as a proxy server in any manner.
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000077
- Vuln IDs
-
- V-41695
- Rule IDs
-
- SV-54272r1_rule
Checks: C-48092r1_chk
Review the web server documentation and deployment configuration to determine if the web server contains documentation, sample code, example applications, or tutorials. Verify the web server install process also offers an option to exclude these elements from installation and provides a uninstall option for their removal. If web server documentation, sample code, example applications, or tutorials are installed or the web server install process does not offer an option to exclude these elements from installation, this is a finding.
Fix: F-47154r1_fix
Use the web server uninstall facility or manually remove any documentation, sample code, example applications, and tutorials.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000078
- Vuln IDs
-
- V-41696
- Rule IDs
-
- SV-54273r1_rule
Checks: C-48093r1_chk
Review the web server documentation to determine the user accounts created when particular features are installed. Verify the deployed configuration to determine which features are installed with the web server. If any accounts exist that are not used by the installed features, this is a finding.
Fix: F-47155r1_fix
Use the web server uninstall facility or manually remove the user accounts not used by the installed web server features.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000079
- Vuln IDs
-
- V-41697
- Rule IDs
-
- SV-54274r1_rule
Checks: C-48094r1_chk
Review the web server documentation and deployment configuration to determine what accounts were installed by the web server installation process. Verify the passwords for these accounts have been set and/or changed from the default passwords. If these accounts still have no password or default passwords, this is a finding.
Fix: F-47156r1_fix
Set passwords for accounts containing no passwords and change the passwords for accounts which still have default passwords.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000080
- Vuln IDs
-
- V-41698
- Rule IDs
-
- SV-54275r1_rule
Checks: C-48095r1_chk
Review the web server documentation and deployment configuration to determine which web server utilities, services, and modules are installed. Verify these options are essential to the operation of the web server. Also, confirm the web server install process offers an option to exclude these utilities, services, and module from installation that are not needed for operation and that there is a uninstall option for their removal. If there are more utilities, services, or modules installed than are needed for the operation of the web server or the web server does not provide an install facility to customize installation, this is a finding.
Fix: F-47157r1_fix
Use the web server uninstall facility or manually remove any utility programs, services, or modules not needed by the web server for operation.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000081
- Vuln IDs
-
- V-41699
- Rule IDs
-
- SV-54276r1_rule
Checks: C-48096r1_chk
Review the web server documentation and deployment configuration to determine if the OS shell is accessible by any MIME types that are enabled. If a user to the web server can invoke OS shell programs, this is a finding.
Fix: F-47158r1_fix
Configure the web server to disable all MIME types that invoke OS shell programs.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000082
- Vuln IDs
-
- V-41700
- Rule IDs
-
- SV-54277r1_rule
Checks: C-48097r1_chk
Review the web server documentation and deployment configuration to determine what script mappings are enabled. Review the scripts used by the web server and the hosted applications. If there are script mappings enabled that are not used by the web server or hosted applications for operation, this is a finding.
Fix: F-47159r1_fix
Disable script mappings that are not needed for web server and hosted application operation.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000083
- Vuln IDs
-
- V-41701
- Rule IDs
-
- SV-54278r1_rule
Checks: C-48098r1_chk
Review the web server documentation and deployment configuration to determine what types of files are being used for the hosted applications. If the web server is not configured to disallow other file types, especially those associated with logs, configuration files, passwords, etc., this is a finding.
Fix: F-47160r1_fix
Configure the web server to only serve file types to the user that are needed by the hosted applications. All other file types must be disabled.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000085
- Vuln IDs
-
- V-41702
- Rule IDs
-
- SV-54279r1_rule
Checks: C-48099r1_chk
Review the web server documentation and deployment configuration to determine if Web Distributed Authoring (WebDAV) is enabled. If WebDAV is enabled, this is a finding.
Fix: F-47161r1_fix
Configure the web server to disable Web Distributed Authoring.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000086
- Vuln IDs
-
- V-41703
- Rule IDs
-
- SV-54280r1_rule
Checks: C-48100r1_chk
Review the web server documentation and configuration to determine the access to server resources given to hosted applications. If hosted applications have access to more system resources than needed for operation, this is a finding.
Fix: F-47162r1_fix
Configure the privileges given to hosted applications to the minimum required for application operation.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-APP-000141-WSR-000087
- Vuln IDs
-
- V-41704
- Rule IDs
-
- SV-54281r1_rule
Checks: C-48101r1_chk
Review the web server documentation and configuration to determine where the document root or home directory for each application hosted by the web server is located. Verify that users of the web server applications, and any scripts running on the user's behalf, are contained to the root or home directory tree. If users of the web server applications, and any scripts running on the user's behalf, are not contained to the root or home directory tree, this is a finding.
Fix: F-47163r1_fix
Configure the web server to contain users and scripts to the home or root directory of each hosted application.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-APP-000142-WSR-000088
- Vuln IDs
-
- V-41705
- Rule IDs
-
- SV-54282r1_rule
Checks: C-48102r1_chk
Review the web server documentation and deployment configuration to determine which ports and protocols are enabled. Verify that the ports and protocols being used are not prohibited and are necessary for the operation of the web server and the hosted applications. If any of the ports or protocols are prohibited or not necessary for web server operation, this is a finding.
Fix: F-47164r1_fix
Configure the web server to disable any ports or protocols that are prohibited by the DoD or are not necessary for web server operation.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-APP-000142-WSR-000089
- Vuln IDs
-
- V-41706
- Rule IDs
-
- SV-54283r1_rule
Checks: C-48103r1_chk
Review the web server documentation and deployment configuration to determine whether the web server is configured to listen on a specified IP address and port. Request a client user try to access the web server on any other available IP addresses on the hosting hardware. If an IP address is not configured on the web server or a client can reach the web server on other IP addresses assigned to the hosting hardware, this is a finding.
Fix: F-47165r1_fix
Configure the web server to only listen on a specified IP address and port.
- RMF Control
- CP-9
- Severity
- L
- CCI
- CCI-000537
- Version
- SRG-APP-000146-WSR-000090
- Vuln IDs
-
- V-41711
- Rule IDs
-
- SV-54288r1_rule
Checks: C-48108r1_chk
Review the web server documentation to determine where files that should be backed up are located. Request the SA show the process for the backup of the web server and determine whether the files are part of the backup. If the files determined to be essential are not part of a regular backup, this is a finding.
Fix: F-47170r1_fix
Configure the web server essential files to be part of a scheduled backup process.
- RMF Control
- CP-9
- Severity
- L
- CCI
- CCI-000537
- Version
- SRG-APP-000146-WSR-000091
- Vuln IDs
-
- V-41712
- Rule IDs
-
- SV-54289r1_rule
Checks: C-48109r1_chk
Verify that the web server is part of a backup process and that no special actions must be taken to complete a backup, such as stopping the web server, stopping services, or making copies of files. If special actions are needed in order to completely back up the web server, this is a finding.
Fix: F-47171r1_fix
Configure the web server to support a complete system and software backup.
- RMF Control
- CP-9
- Severity
- L
- CCI
- CCI-000539
- Version
- SRG-APP-000147-WSR-000092
- Vuln IDs
-
- V-41713
- Rule IDs
-
- SV-54290r1_rule
Checks: C-48110r1_chk
Review the web server documentation to determine where web server configuration files, user password files, keystore, keys, and certificates are located. Request the SA show the process for the backup of the web server and determine whether these files are part of the backup. If the configuration files, user password files, keystore, keys, and certificates are not part of a regular backup, this is a finding.
Fix: F-47172r1_fix
Configure the scheduled backup process to include the web server configuration files, user password files, keystore, keys, and certificates.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000766
- Version
- SRG-APP-000150-WSR-000093
- Vuln IDs
-
- V-41716
- Rule IDs
-
- SV-54293r1_rule
Checks: C-48113r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must use multifactor authentication as part of the user authentication process. If multifactor authentication is not being used, this is a finding.
Fix: F-47175r1_fix
Configure the web server to use multifactor authentication when validating users.
- RMF Control
- IA-4
- Severity
- M
- CCI
- CCI-000795
- Version
- SRG-APP-000163-WSR-000094
- Vuln IDs
-
- V-41728
- Rule IDs
-
- SV-54305r1_rule
Checks: C-48125r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must disable user accounts after a definable period of inactivity. If the web server is not configured to disable inactive accounts, this is a finding.
Fix: F-47187r1_fix
Configure the web server to disable user accounts after a defined period of inactivity.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- SRG-APP-000175-WSR-000095
- Vuln IDs
-
- V-41730
- Rule IDs
-
- SV-54307r1_rule
Checks: C-48127r1_chk
Review the web server documentation and deployed configuration to determine whether the web server provides PKI functionality that validates certificates by constructing a certification path with status information to an accepted trust anchor. If PKI is not being used, this is NA. If the web server is using PKI, but it does not perform this requirement, this is a finding.
Fix: F-47189r1_fix
Configure the web server to validate certificates using a trusted certificate path with status information to an accepted trust anchor.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- SRG-APP-000176-WSR-000096
- Vuln IDs
-
- V-41731
- Rule IDs
-
- SV-54308r1_rule
Checks: C-48128r1_chk
Review the web server documentation and deployed configuration to determine whether the web server contains a private key and where the private key is stored. If the web server does not have a private key, this is NA. If the private key is not protected and is accessible by non-privileged accounts, this is a finding.
Fix: F-47190r1_fix
Configure the web server to protect the private key allowing only access by privileged accounts.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- SRG-APP-000177-WSR-000098
- Vuln IDs
-
- V-41732
- Rule IDs
-
- SV-54309r1_rule
Checks: C-48129r1_chk
Review the web server documentation and deployed configuration to determine whether the web server is performing user validation through PKI-based authentication. If the web server is not performing user management or is not configured to use PKI-based authentication, this is NA. If the web server is only performing PKI-based authentication, and not mapping the token to a user, this is a finding.
Fix: F-47191r1_fix
Configure the web server to map the PKI-authenticated identity to an authorized user.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- SRG-APP-000166-WSR-000099
- Vuln IDs
-
- V-41733
- Rule IDs
-
- SV-54310r1_rule
Checks: C-48130r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must also enforce DoD requirements for the number of uppercase letters in a password. If the number of required uppercase password characters is not according to the DoD requirement, this is a finding.
Fix: F-47192r1_fix
Configure the web server to require the DoD-defined number of uppercase characters in user passwords.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- SRG-APP-000167-WSR-000100
- Vuln IDs
-
- V-41734
- Rule IDs
-
- SV-54311r1_rule
Checks: C-48131r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must also enforce DoD requirements for the number of lowercase letters in a password. If the number of required lowercase password characters is not according to the DoD requirement, this is a finding.
Fix: F-47193r1_fix
Configure the web server to require the DoD-defined number of lowercase characters in user passwords.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- SRG-APP-000168-WSR-000101
- Vuln IDs
-
- V-41735
- Rule IDs
-
- SV-54312r1_rule
Checks: C-48132r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must also enforce DoD requirements for the number of numeric characters in a password. If the number of required numeric password characters is not according to the DoD requirement, this is a finding.
Fix: F-47194r1_fix
Configure the web server to require the DoD-defined number of numeric characters in user passwords.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000195
- Version
- SRG-APP-000170-WSR-000102
- Vuln IDs
-
- V-41736
- Rule IDs
-
- SV-54313r1_rule
Checks: C-48133r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. If the web server is the user authenticator and manager, verify that the number of characters that need to be changed to generate a valid new password is set to that defined by the DoD. If the number of characters needed to be changed in a password does not meet the DoD requirement, this is a finding.
Fix: F-47195r1_fix
Configure the web server to force a user to change a DoD-defined number of characters when creating a new password.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000196
- Version
- SRG-APP-000171-WSR-000103
- Vuln IDs
-
- V-41737
- Rule IDs
-
- SV-54314r1_rule
Checks: C-48134r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. If the web server is the user authenticator and manager, verify that the passwords are stored in an encrypted format. If the passwords are not stored encrypted, this is a finding.
Fix: F-47196r1_fix
Configure the web server to encrypt passwords when stored.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- SRG-APP-000172-WSR-000104
- Vuln IDs
-
- V-41738
- Rule IDs
-
- SV-54315r1_rule
Checks: C-48135r1_chk
Review the web server documentation and deployed configuration to determine whether authentication data is being passed to or from the web server. If the transmission of the authentication data is not encrypted, this is a finding.
Fix: F-47197r1_fix
Configure the web server to encrypt the transmission authentication data.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000198
- Version
- SRG-APP-000173-WSR-000105
- Vuln IDs
-
- V-41739
- Rule IDs
-
- SV-54316r1_rule
Checks: C-48136r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. If the web server is the user authenticator and manager, verify that a password minimum lifetime setting is in place. If there is no password minimum lifetime in place, this is a finding.
Fix: F-47198r1_fix
Configure the web server to enforce a password minimum lifetime.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000199
- Version
- SRG-APP-000174-WSR-000106
- Vuln IDs
-
- V-41740
- Rule IDs
-
- SV-54317r1_rule
Checks: C-48137r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. If the web server is the user authenticator and manager, verify that a password maximum lifetime setting is in place. If there is no password maximum lifetime in place, this is a finding.
Fix: F-47199r1_fix
Configure the web server to enforce a password maximum lifetime.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000200
- Version
- SRG-APP-000165-WSR-000107
- Vuln IDs
-
- V-41741
- Rule IDs
-
- SV-54318r1_rule
Checks: C-48138r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. If the web server is the user authenticator and manager, verify that a password reuse setting is in place. If there is no password reuse setting in place, this is a finding.
Fix: F-47200r1_fix
Configure the web server to enforce password reuse.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- SRG-APP-000164-WSR-000108
- Vuln IDs
-
- V-41742
- Rule IDs
-
- SV-54319r1_rule
Checks: C-48139r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. If the web server is the user authenticator and manager, verify that a password minimum length setting is in place. If there is no password minimum length setting in place, this is a finding.
Fix: F-47201r1_fix
Configure the web server to enforce a password minimum length.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001619
- Version
- SRG-APP-000169-WSR-000109
- Vuln IDs
-
- V-41743
- Rule IDs
-
- SV-54320r1_rule
Checks: C-48140r1_chk
Review the web server documentation and configuration to determine whether the web server is performing user management. If the web server is not being used for user management, this is NA. When the web server is also performing user management functionality for the hosted applications, the web server must also enforce DoD requirements for the number of special characters in a password. If the number of special characters in the password does not meet the DoD requirement, this is a finding.
Fix: F-47202r1_fix
Configure the web server to require the DoD-defined number of special characters in user passwords.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SRG-APP-000179-WSR-000110
- Vuln IDs
-
- V-41745
- Rule IDs
-
- SV-54322r1_rule
Checks: C-48142r1_chk
Review web server documentation and deployed configuration to determine whether the encryption modules utilized for storage of data are FIPS 140-2 compliant. Reference the following NIST site to identify validated encryption modules: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm If the encryption modules used for storage of data are not FIPS 140-2 validated, this is a finding.
Fix: F-47204r1_fix
Configure the web server to utilize FIPS 140-2 approved encryption modules when the web server is storing data.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SRG-APP-000179-WSR-000111
- Vuln IDs
-
- V-41746
- Rule IDs
-
- SV-54323r1_rule
Checks: C-48143r1_chk
Review web server documentation and deployed configuration to determine whether the encryption modules utilized for authentication are FIPS 140-2 compliant. Reference the following NIST site to identify validated encryption modules: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm If the encryption modules used for authentication are not FIPS 140-2 validated, this is a finding.
Fix: F-47205r1_fix
Configure the web server to utilize FIPS 140-2 approved encryption modules when authenticating users and processes.
- RMF Control
- MP-4
- Severity
- M
- CCI
- CCI-001019
- Version
- SRG-APP-000188-WSR-000113
- Vuln IDs
-
- V-41765
- Rule IDs
-
- SV-54342r1_rule
Checks: C-48153r1_chk
Review the web server documentation and deployed configuration to determine whether the web server is authorizing and managing users. If the web server is not authorizing and managing users, this is NA. If the web server is the user authenticator and manager, verify that stored user identifiers and passwords are being encrypted by the web server. If the user information is not being encrypted when stored, this is a finding.
Fix: F-47224r1_fix
Configure the web server to encrypt the user identifiers and passwords when storing them on digital media.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- SRG-APP-000190-WSR-000114
- Vuln IDs
-
- V-41768
- Rule IDs
-
- SV-54345r1_rule
Checks: C-48156r1_chk
Review the web server documentation and deployed configuration to verify the system terminates network connections on hosted application close or after an organization-defined time period of inactivity. If communications are not terminated on hosted application close or after an organization-defined time period of inactivity, this is a finding.
Fix: F-47227r1_fix
Configure the web server to terminate network connections on hosted application close or after the organization-defined time period of inactivity.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-001144
- Version
- SRG-APP-000196-WSR-000118
- Vuln IDs
-
- V-41774
- Rule IDs
-
- SV-54351r1_rule
Checks: C-48162r1_chk
Review policy documents to identify classified data that is compartmentalized and requires cryptographic protection. Review the web server documentation and deployed configuration to identify the encryption modules utilized to protect the compartmentalized data. If the encryption modules used to protect the compartmentalized data are not compliant with the data, this is a finding.
Fix: F-47233r1_fix
Configure the web server to utilize cryptography when protecting classified compartmentalized data.
- RMF Control
- SC-14
- Severity
- M
- CCI
- CCI-001149
- Version
- SRG-APP-000201-WSR-000121
- Vuln IDs
-
- V-41777
- Rule IDs
-
- SV-54354r1_rule
Checks: C-48165r1_chk
Review the web server deployed configuration to determine whether the web server is displaying publicly hosted information. Also, determine whether the web server is separated physically and logically from private assets. If the web server is not isolated from private assets, this is a finding.
Fix: F-47236r1_fix
Physically and logically isolate the web server from private assets.
- RMF Control
- SC-14
- Severity
- M
- CCI
- CCI-001149
- Version
- SRG-APP-000201-WSR-000122
- Vuln IDs
-
- V-41778
- Rule IDs
-
- SV-54355r1_rule
Checks: C-48166r1_chk
Review the web server documentation and deployed configuration to determine whether the web server banner can be minimized or customized. If the web server is not configured to minimize the banner or the banner is not customized, this is a finding.
Fix: F-47237r1_fix
Configure the web server to minimize the information given in the banner, or customize the banner to disguise the web server.
- RMF Control
- SC-14
- Severity
- M
- CCI
- CCI-001149
- Version
- SRG-APP-000201-WSR-000123
- Vuln IDs
-
- V-41779
- Rule IDs
-
- SV-54356r1_rule
Checks: C-48167r1_chk
Verify the site's network diagram and visually check the web server to ensure that the web server is located on a separate controlled access subnet and is not a part of the public DMZ that houses web servers for public use. In addition, the web server needs to be isolated via a controlled access mechanism from the local general population LAN. If the web server is not isolated, this is a finding.
Fix: F-47238r1_fix
Locate the web server so that it is isolated and protected from public use.
- RMF Control
- SC-14
- Severity
- M
- CCI
- CCI-001149
- Version
- SRG-APP-000201-WSR-000124
- Vuln IDs
-
- V-41780
- Rule IDs
-
- SV-54357r1_rule
Checks: C-48168r1_chk
Review the web server documentation and deployed configuration to determine whether the web server is configured to not respond to public search engines. If the web server will respond to public search engines, this is a finding.
Fix: F-47239r1_fix
Configure the web server to not respond to public search engines.
- RMF Control
- SC-14
- Severity
- L
- CCI
- CCI-001149
- Version
- SRG-APP-000201-WSR-000125
- Vuln IDs
-
- V-41781
- Rule IDs
-
- SV-54358r1_rule
Checks: C-48169r1_chk
Review the web server documentation and deployed configuration to determine whether indexing is being used and on which directories. If indexing is enabled and not limited to the content directory, this is a finding.
Fix: F-47240r1_fix
Configure the web server to either disable indexing or limit indexing to only the content directory.
- RMF Control
- SC-14
- Severity
- M
- CCI
- CCI-001149
- Version
- SRG-APP-000201-WSR-000126
- Vuln IDs
-
- V-41782
- Rule IDs
-
- SV-54359r1_rule
Checks: C-48170r1_chk
Review the web server documentation and deployed configuration to determine whether session IDs are protected from non-privileged users. If session IDs are not protected, this is a finding.
Fix: F-47241r1_fix
Configure the web server to protect session IDs from non-privileged users.
- RMF Control
- SC-17
- Severity
- M
- CCI
- CCI-001159
- Version
- SRG-APP-000205-WSR-000165
- Vuln IDs
-
- V-41786
- Rule IDs
-
- SV-54363r1_rule
Checks: C-48174r1_chk
Review the web server documentation and deployed configuration to determine if the web server is following DoD and NSS certificate policies to obtain public keys. If the web server is not following the DoD and NSS policies, this is a finding.
Fix: F-47245r1_fix
Configure the web server to follow the DoD and NSS certificate policies to obtain public key certificates.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- SRG-APP-000211-WSR-000129
- Vuln IDs
-
- V-41794
- Rule IDs
-
- SV-54371r1_rule
Checks: C-48182r1_chk
Review the web server documentation and deployed configuration to determine whether hosted application functionality is separated from web server management functions. If the functions are not separated, this is a finding.
Fix: F-47253r1_fix
Configure the web server to separate the hosted applications from web server management functionality.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001083
- Version
- SRG-APP-000212-WSR-000130
- Vuln IDs
-
- V-41795
- Rule IDs
-
- SV-54372r1_rule
Checks: C-48183r1_chk
Review the web server documentation and deployed configuration to verify whether management-related functionality is presented to non-privileged users. If the management functionality is presented to non-privileged users, this is a finding.
Fix: F-47254r1_fix
Configure the web server to prevent the presentation of management-related functions to non-privileged users.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001184
- Version
- SRG-APP-000219-WSR-000131
- Vuln IDs
-
- V-41801
- Rule IDs
-
- SV-54378r1_rule
Checks: C-48189r1_chk
Review the web server documentation and deployed configuration to determine whether two-way authentication is being used. If the web server is not using two-way authentication, this is NA. If two-way authentication is being used, verify that the authentication is maintained during the entire session. If the authentication is not maintained during the entire session, this is a finding.
Fix: F-47260r1_fix
Configure the web server to maintain authentication during the entire session during a two-way authenticated session.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- SRG-APP-000225-WSR-000140
- Vuln IDs
-
- V-41811
- Rule IDs
-
- SV-54388r1_rule
Checks: C-48199r1_chk
Review the web server documentation, deployed configuration, and risk analysis documentation to determine whether the web server will fail to known states for defined failures. If the web server will not fail to known states for defined failures, this is a finding.
Fix: F-47270r1_fix
Configure the web server to fail to the states of operation during defined failures found in the risk analysis.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- SRG-APP-000225-WSR-000141
- Vuln IDs
-
- V-41812
- Rule IDs
-
- SV-54389r1_rule
Checks: C-48200r1_chk
Review the web server documentation, deployed configuration, and risk analysis documentation to ensure the web server is configured to provide clustering functionality. If the web server is not configured to provide clustering or some form of failover functionality, this is a finding.
Fix: F-47271r1_fix
Configure the web server to provide application failover, or participate in a web cluster which provides failover.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- SRG-APP-000225-WSR-000142
- Vuln IDs
-
- V-41813
- Rule IDs
-
- SV-54390r1_rule
Checks: C-48201r1_chk
Review the web server documentation and deployed configuration to locate all the web document directories. Verify that each web document directory contains a default web page. If a document directory does not contain a default web page, this is a finding.
Fix: F-47272r1_fix
Place a default web page in every web document directory.
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- SRG-APP-000231-WSR-000144
- Vuln IDs
-
- V-41815
- Rule IDs
-
- SV-54392r1_rule
Checks: C-48203r1_chk
Review the web server documentation and deployed configuration to locate where potential data at rest is stored. Verify that the data is encrypted using a DoD-accepted algorithm to protect the confidentiality and integrity of the information. If the data is not encrypted using a DoD-accepted algorithm, this is a finding.
Fix: F-47274r1_fix
Use a DoD-accepted algorithm to encrypt data at rest to protect the information's confidentiality and integrity.
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- SRG-APP-000233-WSR-000146
- Vuln IDs
-
- V-41821
- Rule IDs
-
- SV-54398r1_rule
Checks: C-48209r1_chk
Review the web server documentation and deployed configuration to determine where the document directory is located for each hosted application. If the document directory is not separated from the web server's system files, this is a finding.
Fix: F-47280r1_fix
Configure the web server to separate the document directories from the web server system files.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001092
- Version
- SRG-APP-000245-WSR-000147
- Vuln IDs
-
- V-41831
- Rule IDs
-
- SV-54408r1_rule
Checks: C-48219r1_chk
Review the web server documentation and deployed configuration to determine where the process ID is stored and which utilities are used to start/stop the web server. Determine whether the process ID and the utilities are protected from non-privileged users. If they are not protected, this is a finding.
Fix: F-47290r1_fix
Configure the web server to protect the process ID and the utilities used for starting/stopping the web server from non-privileged users.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001092
- Version
- SRG-APP-000245-WSR-000148
- Vuln IDs
-
- V-41832
- Rule IDs
-
- SV-54409r1_rule
Checks: C-48220r1_chk
Review the web server documentation and deployed configuration to determine what parameters are set to tune the web server. Review the hosted applications along with risk analysis documents to determine the expected user traffic. If the web server has not been tuned to avoid a DoS, this is a finding.
Fix: F-47291r1_fix
Analyze the expected user traffic for the hosted applications. Tune the web server to avoid a DoS condition under normal user traffic to the hosted applications.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001126
- Version
- SRG-APP-000254-WSR-000150
- Vuln IDs
-
- V-41845
- Rule IDs
-
- SV-54422r1_rule
Checks: C-48233r1_chk
Review the web server documentation and deployed configuration to determine the settings needed to add a layer of security should a boundary protection device fail. If the web server does not have any settings in place to secure the web server in the event of a boundary protection device failure, this is a finding.
Fix: F-47304r1_fix
Configure the web server with settings that will protect the web server environment should a boundary protection device fail.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- SRG-APP-000264-WSR-000151
- Vuln IDs
-
- V-41846
- Rule IDs
-
- SV-54423r1_rule
Checks: C-48234r1_chk
Review the web server documentation and deployed configuration to determine whether the transmission of data between the web server and external devices is encrypted. If the web server does not encrypt the transmission, this is a finding.
Fix: F-47305r1_fix
Configure the web server to encrypt the transmission of data between the web server and external devices.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- SRG-APP-000264-WSR-000152
- Vuln IDs
-
- V-41847
- Rule IDs
-
- SV-54424r1_rule
Checks: C-48235r1_chk
Review the web server documentation and deployed configuration to determine whether the session identifier is being sent to the client encrypted. If the web server does not encrypt the session identifier, this is a finding.
Fix: F-47306r1_fix
Configure the web server to encrypt the session identifier for transmission to the client.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- SRG-APP-000264-WSR-000153
- Vuln IDs
-
- V-41848
- Rule IDs
-
- SV-54425r1_rule
Checks: C-48236r1_chk
Review the web server documentation and deployed configuration to determine whether cookies are being sent to the client encrypted and compressed. If the web server is using encryption and compression to transmit cookies, this is a finding.
Fix: F-47307r1_fix
Configure the web server to turn off cookie compression.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- SRG-APP-000264-WSR-000154
- Vuln IDs
-
- V-41849
- Rule IDs
-
- SV-54426r1_rule
Checks: C-48237r1_chk
Review the web server documentation and deployed configuration to determine how to disable client-side scripts from reading cookies. If the web server is not configured to disallow client-side scripts from reading cookies, this is a finding.
Fix: F-47308r1_fix
Configure the web server to disallow client-side scripts the capability of reading cookie information.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- SRG-APP-000264-WSR-000155
- Vuln IDs
-
- V-41850
- Rule IDs
-
- SV-54427r1_rule
Checks: C-48238r1_chk
Review the web server documentation and deployed configuration to verify that cookies are encrypted before transmission. If the web server is not configured to encrypt cookies, this is a finding.
Fix: F-47309r1_fix
Configure the web server to encrypt cookies before transmission.
- RMF Control
- SI-10
- Severity
- M
- CCI
- CCI-001310
- Version
- SRG-APP-000251-WSR-000157
- Vuln IDs
-
- V-41852
- Rule IDs
-
- SV-54429r1_rule
Checks: C-48240r1_chk
Review the web server documentation and deployed configuration to determine what the data set is for data entry. If the web server does not limit the data set used for data entry, this is a finding.
Fix: F-47311r1_fix
Configure the web server to only accept the character sets expected by the hosted applications.
- RMF Control
- SI-11
- Severity
- L
- CCI
- CCI-001311
- Version
- SRG-APP-000265-WSR-000158
- Vuln IDs
-
- V-41853
- Rule IDs
-
- SV-54430r1_rule
Checks: C-48241r1_chk
Review the web server documentation and deployed configuration to determine whether the system identifies potentially security-relevant error conditions. If these security-relevant error conditions are not identified, this is a finding.
Fix: F-47312r1_fix
Configure the web server to identify potentially security-relevant error conditions.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- SRG-APP-000266-WSR-000159
- Vuln IDs
-
- V-41854
- Rule IDs
-
- SV-54431r1_rule
Checks: C-48242r1_chk
Review the web server documentation and deployed configuration to determine whether the web server offers different modes of operation that will minimize the identity of the web server, patches, loaded modules, and directory paths given to clients on error conditions. If the web server is not configured to minimize the information given to clients, this is a finding.
Fix: F-47313r1_fix
Configure the web server to minimize the information provided to the client in warning and error messages.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- SRG-APP-000266-WSR-000160
- Vuln IDs
-
- V-41855
- Rule IDs
-
- SV-54432r1_rule
Checks: C-48243r1_chk
Review the web server documentation and deployed configuration to determine if debugging and trace information are disabled. If the web server is not configured with debugging and trace information disabled, this is a finding.
Fix: F-47314r1_fix
Configure the web server to minimize the information given to clients on error conditions by disabling debugging and trace information.
- RMF Control
- SI-13
- Severity
- L
- CCI
- CCI-001328
- Version
- SRG-APP-000268-WSR-000161
- Vuln IDs
-
- V-41857
- Rule IDs
-
- SV-54434r1_rule
Checks: C-48245r1_chk
Review the web server documentation, deployment configuration, and organizational disaster plan to determine the web server configurations to implement the organization's disaster plan. If the web server does not alarm when a failure takes place or does not enforce the disaster plan, this is a finding.
Fix: F-47316r1_fix
Configure the web server to alarm on organizationally defined failures or to implement the organization's disaster plan.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-APP-999999-WSR-000164
- Vuln IDs
-
- V-41885
- Rule IDs
-
- SV-54462r1_rule
Checks: C-48273r1_chk
Review the web server documentation and deployed configuration to determine whether the web server has been configured to reduce the risks of buffer overflows. If the web server has not been configured to reduce the risk of buffer overflows, this is a finding.
Fix: F-47344r1_fix
Configure the web server to limit the amount of data processed by the web server and to define buffer sizes.