WBLC-10-000272 - Oracle WebLogic must be integrated with a tool to implement multi-factor user authentication.

Information

Multifactor authentication is defined as: using two or more factors to achieve authentication.

Factors include:
(i) something a user knows (e.g., password/PIN);
(ii) something a user has (e.g., cryptographic identification device, token); or
(iii) something a user is (e.g., biometric). A CAC meets this definition.

Implementing a tool, such as Oracle Access Manager, will implement multi-factor authentication to the application server and tie the authenticated user to a user account (i.e. roles and privileges) assigned to the authenticated user.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install a tool, such as Oracle Access Manager, to handle multi-factor authentication of users.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_WebLogic_Server_12c_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-235999r961863_rule, STIG-ID|WBLC-10-000272, STIG-Legacy|SV-70641, STIG-Legacy|V-56387, Vuln-ID|V-235999

Plugin: Windows

Control ID: 147983ef2192734c0780f7f4095cc389bd0fba4c1aab5298646e0bc5ab3600d4