CCI|CCI-001312

Title

The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.

Reference Item Details

Category: 2009

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AS24-U1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.UnixDISA STIG Apache Server 2.4 Unix Server v2r6 Middleware
AS24-U1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.UnixDISA STIG Apache Server 2.4 Unix Server v2r6
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - LogLevelUnixDISA STIG Apache Server 2.4 Unix Server v2r6 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - LogLevelUnixDISA STIG Apache Server 2.4 Unix Server v2r6
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - TraceEnableUnixDISA STIG Apache Server 2.4 Unix Server v2r6 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - TraceEnableUnixDISA STIG Apache Server 2.4 Unix Server v2r6
AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.UnixDISA STIG Apache Server 2.4 Unix Site v2r4
AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.UnixDISA STIG Apache Server 2.4 Unix Site v2r4 Middleware
AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.UnixDISA STIG Apache Server 2.4 Unix Site v2r4
AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.UnixDISA STIG Apache Server 2.4 Unix Site v2r4 Middleware
AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.UnixDISA STIG Apache Server 2.4 Unix Site v2r4
AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.UnixDISA STIG Apache Server 2.4 Unix Site v2r4 Middleware
AS24-W1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.WindowsDISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.WindowsDISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.WindowsDISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Generate Error Messages without Exploitable InformationUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Generate Error Messages without Exploitable InformationUnixNIST macOS Catalina v1.5.0 - All Profiles
DB2X-00-006200 - DB2 must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.IBM_DB2DBDISA STIG IBM DB2 v10.5 LUW v2r1 Database
DTBC-0068 - Chrome development tools must be disabled.WindowsDISA STIG Google Chrome v2r8
DTBI1135-IE11 - Internet Explorer Development Tools Must Be Disabled.WindowsDISA STIG IE 11 v2r4
EP11-00-006500 - The EDB Postgres Advanced Server must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.PostgreSQLDBEDB PostgreSQL Advanced Server v11 DB Audit v2r2
FFOX-00-000015 - Firefox development tools must be disabled.UnixDISA STIG Mozilla Firefox MacOS v6r5
FFOX-00-000015 - Firefox development tools must be disabled.WindowsDISA STIG Mozilla Firefox Windows v6r5
FFOX-00-000015 - Firefox development tools must be disabled.UnixDISA STIG Mozilla Firefox Linux v6r5
IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.WindowsDISA IIS 10.0 Site v2r9
IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.WindowsDISA IIS 10.0 Site v2r9
IIST-SV-000139 - The IIS 10.0 web server Indexing must only index web content.WindowsDISA IIS 10.0 Server v2r10
IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.WindowsDISA IIS 10.0 Server v2r10
IIST-SV-000210 - HTTPAPI Server version must be removed from the HTTP Response Header information.WindowsDISA IIS 10.0 Server v2r10
IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.WindowsDISA IIS 10.0 Server v2r10
IISW-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 website, patches, loaded modules, and directory paths.WindowsDISA IIS 8.5 Site v2r9
IISW-SI-000234 - Debugging and trace information used to diagnose the IIS 8.5 website must be disabled.WindowsDISA IIS 8.5 Site v2r9
IISW-SV-000139 - The IIS 8.5 web server Indexing must only index web content.WindowsDISA IIS 8.5 Server v2r7
IISW-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 web server, patches, loaded modules, and directory paths.WindowsDISA IIS 8.5 Server v2r7
JUSX-AG-000132 - The Juniper SRX Services Gateway Firewall must configure ICMP to meet DoD requirements.JuniperDISA Juniper SRX Services Gateway ALG v2r1
MD3X-00-000520 - MongoDB must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.UnixDISA STIG MongoDB Enterprise Advanced 3.x v2r1 OS
MD4X-00-004200 - MongoDB must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.UnixDISA STIG MongoDB Enterprise Advanced 4.x v1r2 OS
Monterey - Generate Error Messages without Exploitable InformationUnixNIST macOS Monterey v1.0.0 - All Profiles
OH12-1X-000346 - OHS must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.UnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000347 - OHS must have the ServerSignature directive disabled.UnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000348 - OHS must have the ServerTokens directive set to limit the response header.UnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - AllowUnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - AllowOverrideUnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - LimitExceptUnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - LimitExcept > DenyUnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - OptionsUnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - OrderUnixDISA STIG Oracle HTTP Server 12.1.3 v2r2
OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 400UnixDISA STIG Oracle HTTP Server 12.1.3 v2r2