Item Search

NameAudit NamePluginCategory
2.1 Alter the Advertised server.info StringCIS Apache Tomcat 10 L2 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.4 Ensure the Status Module Is DisabledCIS Apache HTTP Server 2.4 v2.3.0 L1Unix

CONFIGURATION MANAGEMENT

2.6 Ensure the Proxy Modules Are DisabledCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

2.6 Ensure the Proxy Modules Are DisabledCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.6 Ensure the Proxy Modules Are DisabledCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.4 v2.3.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

AS24-W2-000240 - The Apache web server must not perform user management for hosted applications.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000310 - The Apache web server must allow the mappings to unused and vulnerable scripts to be removed.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000440 - Anonymous user access to the Apache web server application directories must be prohibited.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application - Header HttpOnly SecureDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000540 - The Apache web server must augment re-creation to a stable and known baseline.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000580 - The Apache web server document directory must be in a separate partition from the Apache web servers system files.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W2-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

ACCESS CONTROL

AS24-W2-000690 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

ACCESS CONTROL

AS24-W2-000780 - The Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000870 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie dataDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000880 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookiesDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA022 A22 - The KeepAlive directive must be enabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA024 A22 - The KeepAliveTimeout directive must be defined.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA026 A22 - The httpd.conf StartServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA030 A22 - The httpd.conf MaxSpareServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA032 A22 - The httpd.conf MaxClients directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - test-cgiDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - -+IncludesNOEXEC|-IncludesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - Options NoneDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA058 A22 - Directory indexing must be disabled on directories not containing index files.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA000-WWA064 A22 - The HTTP request header field size must be limited.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA060 A22 - A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ Extension.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA120 A22 - Administrative users and groups that have access rights to the web server must be documented.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA230 A22 - The Web site software used with the web server must have all applicable security patches applied and documented.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00500 A22 - Active software modules must be minimized.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00515 A22 - Automatic directory indexing must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA00530 A22 - The process ID (PID) file must be properly securedDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00545 A22 - Web server options for the OS root must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA00547 A22 - The ability to override the access configuration for the OS root directory must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA00550 A22 - The TRACE method must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA00555 A22 - The web server must be configured to listen on a specific IP address and port - [::ffff:0.0.0.0]:80DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00560 A22 - The URL-path name must be set to the file path name or the directory path name.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WBLC-05-000176 - Oracle WebLogic must use cryptographic modules that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when encrypting stored data - JAVA_OPTIONSOracle WebLogic Server 12c Windows v2r2Windows

IDENTIFICATION AND AUTHENTICATION

WBLC-05-000177 - Oracle WebLogic must utilize FIPS 140-2 approved encryption modules when authenticating users and processes - PRE_CLASSPATHOracle WebLogic Server 12c Windows v2r2Windows

IDENTIFICATION AND AUTHENTICATION

WG040 A22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG145 A22 - The private web server must use an approved DoD certificate validation process.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG190 A22 - Web server software must be a vendor-supported version.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG220 A22 - Web administration tools must be restricted to the web manager and the web manager's designees - AccessConfigDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG280 - The access control files are owned by a privileged web server account - HTACCESS_DIRDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG520 A22 - Web server and/or operating system information must be protected.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix