CIS IBM WebSphere Liberty v1.0.0 L1

Audit Details

Name: CIS IBM WebSphere Liberty v1.0.0 L1

Updated: 10/22/2025

Authority: CIS

Plugin: Unix

Revision: 1.2

Estimated Item Count: 106

File Details

Filename: CIS_IBM_WebSphere_Liberty_v1.0.0_L1.audit

Size: 337 kB

MD5: 8e6778d7b4a64789e5f25d650f3940da
SHA256: e0f5774032aaf8674c0ca2d09cec77acbc2457e13d925c3c610cd8ba95b5ed26

Audit Changelog

 
Revision 1.2

Oct 22, 2025

Informational Update
  • 1.5 Ensure Websphere Liberty Server Output is not set to the default value
  • 1.9 Ensure that the 'onConflict attribute' is set to 'IGNORE' to restrict config file overwrites
  • 10.1 Ensure Unused Features are Removed
  • 10.2 Ensure Passwords are Encrypted
  • 10.4 Ensure 'keysPassword' is set to a custom password for ltpa keys
  • 10.5 Ensure 'security-role' is defined for role based authorization checks for Web and EJB applications
  • 2.3 Ensure that the LDAP connection uses TLS
  • 4.2.8 Ensure that CA (Certificate Authority) certificates are used
  • 4.4.10 Ensure 'trustedHeaderOrigin' is set to trusted host names and IP addresses
  • 4.4.13 Ensure application security feature is enabled
  • 4.4.17 Ensure uncovered http methods are denied
  • 4.4.19 Ensure server headers on requests are removed
  • 4.4.9 Ensure ''trustedSensitiveHeaderOrigin'' is set to trusted host names and IP addresses for sensitive data
  • 6.3 Ensure CallbackHandler is used to access private keys in keystore files
Miscellaneous
  • Metadata updated.
  • Variables updated.
Revision 1.1

Sep 12, 2025

Miscellaneous
  • Metadata updated.
  • References updated.