STIGQter STIGQter: STIG Summary: Database Security Requirements Guide Version: 3 Release: 1 Benchmark Date: 22 Jan 2021:

The DBMS must recognize only system-generated session identifiers.

DISA Rule

SV-206566r617447_rule

Vulnerability Number

V-206566

Group Title

SRG-APP-000223

Rule Version

SRG-APP-000223-DB-000168

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Utilize a DBMS product that only recognizes session identifiers that are system-generated.

Check Contents

Review DBMS settings and vendor documentation to determine whether the DBMS recognizes session identifiers that are not system-generated.

If the DBMS recognizes session identifiers that are not system generated, this is a finding.

Vulnerability Number

V-206566

Documentable

False

Rule Version

SRG-APP-000223-DB-000168

Severity Override Guidance

Review DBMS settings and vendor documentation to determine whether the DBMS recognizes session identifiers that are not system-generated.

If the DBMS recognizes session identifiers that are not system generated, this is a finding.

Check Content Reference

M

Target Key

2902

Comments