OH12-1X-000212 - OHS must be certified with accompanying Fusion Middleware products.

Information

OHS is capable of being used with other Oracle products. For the products to work properly and not introduce vulnerabilities or errors, Oracle certifies which versions work with each other. Insisting that the certified versions be installed together in a production environment reduces the possibility of successful attacks, DoS through software system downtime and easier patch management for the SA.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Upgrade or patch OHS or other Oracle Fusion Middleware products to achieve a certified configuration per http://www.oracle.com/technetwork/middleware/fusion-middleware/documentation/fmw-1213certmatrix-2226694.xls.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_HTTP_Server_12-1-3_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-221450r961863_rule, STIG-ID|OH12-1X-000212, STIG-Legacy|SV-79153, STIG-Legacy|V-64663, Vuln-ID|V-221450

Plugin: Unix

Control ID: 81b42f5d39e79f59e2e5e2f639fea3d37cb72aa63c62cf7b5fac3961036b9b29