Audits
Settings
Links
Tenable.io
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Links
Tenable.io
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Audits
References
CCI
CCI-001312
CCI
CCI|CCI-001312
Title
The information system generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2009
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
AS24-U1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5
AS24-U1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - LogLevel
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - LogLevel
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - TraceEnable
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - TraceEnable
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5 Middleware
AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r2 Middleware
AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r2
AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r2 Middleware
AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r2
AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r2 Middleware
AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r2
AS24-W1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r2
AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r2
AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Generate Error Messages without Exploitable Information
Unix
NIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Generate Error Messages without Exploitable Information
Unix
NIST macOS Catalina v1.5.0 - All Profiles
DTBC-0068 - Chrome development tools must be disabled.
Windows
DISA STIG Google Chrome v2r6
DTBI1135-IE11 - Internet Explorer Development Tools Must Be Disabled.
Windows
DISA STIG IE 11 v2r2
FFOX-00-000015 - Firefox development tools must be disabled.
Unix
DISA STIG Mozilla Firefox MacOS v6r3
FFOX-00-000015 - Firefox development tools must be disabled.
Unix
DISA STIG Mozilla Firefox Linux v6r3
FFOX-00-000015 - Firefox development tools must be disabled.
Windows
DISA STIG Mozilla Firefox Windows v6r3
IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.
Windows
DISA IIS 10.0 Site v2r5
IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.
Windows
DISA IIS 10.0 Site v2r5
IIST-SV-000139 - The IIS 10.0 web server Indexing must only index web content.
Windows
DISA IIS 10.0 Server v2r5
IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
Windows
DISA IIS 10.0 Server v2r5
IIST-SV-000210 - HTTPAPI Server version must be removed from the HTTP Response Header information.
Windows
DISA IIS 10.0 Server v2r5
IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.
Windows
DISA IIS 10.0 Server v2r5
IISW-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 website, patches, loaded modules, and directory paths.
Windows
DISA IIS 8.5 Site v2r5
IISW-SI-000234 - Debugging and trace information used to diagnose the IIS 8.5 website must be disabled.
Windows
DISA IIS 8.5 Site v2r5
IISW-SV-000139 - The IIS 8.5 web server Indexing must only index web content.
Windows
DISA IIS 8.5 Server v2r3
IISW-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 web server, patches, loaded modules, and directory paths.
Windows
DISA IIS 8.5 Server v2r3
MD3X-00-000520 - MongoDB must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
Unix
DISA STIG MongoDB Enterprise Advanced 3.x v2r1 OS
MD4X-00-004200 - MongoDB must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
Unix
DISA STIG MongoDB Enterprise Advanced 4.x v1r1 OS
Monterey - Generate Error Messages without Exploitable Information
Unix
NIST macOS Monterey v1.0.0 - All Profiles
OH12-1X-000346 - OHS must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000347 - OHS must have the ServerSignature directive disabled.
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000348 - OHS must have the ServerTokens directive set to limit the response header.
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - Allow
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - AllowOverride
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - LimitExcept
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - LimitExcept > Deny
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - Options
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000350 - OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients - Order
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 400
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 401
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 403
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1
OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 404
Unix
DISA STIG Oracle HTTP Server 12.1.3 v2r1