SQL6-D0-012700 - When updates are applied to SQL Server software, any software components that have been replaced or made unnecessary must be removed.

Information

Previous versions of DBMS components that are not removed from the information system after updates have been installed may be exploited by adversaries.

Some DBMSs' installation tools may remove older versions of software automatically from the information system. In other cases, manual review and removal will be required. In planning installations and upgrades, organizations must include steps (automated, manual, or both) to identify and remove the outdated modules.

A transition period may be necessary when both the old and the new software are required. This should be taken into account in the planning.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove all features that are not required.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_SQL_Server_2016_Y24M01_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(6), CAT|II, CCI|CCI-002617, Rule-ID|SV-213993r879825_rule, STIG-ID|SQL6-D0-012700, STIG-Legacy|SV-93953, STIG-Legacy|V-79247, Vuln-ID|V-213993

Plugin: MS_SQLDB

Control ID: af6093d199cad2240c3d8af4af814668f2b2a536d9835e32404703ce6dd2c2a4