1. Home
  2. Security Hardening
  3. DISA IBM WebSphere Traditional 9 STIG V1R1
  4. WBSP-AS-000240 – The WebSphere Application Server users in a LDAP user registry group must be authorized for that group.

WBSP-AS-000240 – The WebSphere Application Server users in a LDAP user registry group must be authorized for that group.

Details

Preventing non-privileged users from executing privileged functions mitigates the risk that unauthorized individuals or processes may gain unnecessary access to information or privileges.

Restricting non-privileged users also prevents an attacker, who has gained access to a non-privileged account, from elevating privileges, creating accounts, and performing system checks and maintenance.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

In the LDAP server admin console, assign WebSphere users to the appropriate WebSphere group.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles