STIGQter STIGQter: STIG Summary: Apache Server 2.4 Windows Server Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

All accounts installed with the Apache web server software and tools must have passwords assigned and default passwords changed.

DISA Rule

SV-214357r505936_rule

Vulnerability Number

V-214357

Group Title

SRG-APP-000516-WSR-000079

Rule Version

AS24-W1-000940

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Access "Apps" menu. Under "Administrative Tools", select "Computer Management".

In left pane, expand "Local Users and Groups" and click on "Users".

Change passwords for any local accounts that are present and are used by Apache Web Server.

Develop an internal process for changing passwords on a regular basis.

Check Contents

Access "Apps" menu. Under "Administrative Tools", select "Computer Management".

In left pane, expand "Local Users and Groups" and click on "Users".

Review the local users listed in the middle pane.

If any local accounts are present and are used by Apache Web Server, verify with System Administrator that default passwords have been changed.

If passwords have not been changed from the default, this is a finding.

Vulnerability Number

V-214357

Documentable

False

Rule Version

AS24-W1-000940

Severity Override Guidance

Access "Apps" menu. Under "Administrative Tools", select "Computer Management".

In left pane, expand "Local Users and Groups" and click on "Users".

Review the local users listed in the middle pane.

If any local accounts are present and are used by Apache Web Server, verify with System Administrator that default passwords have been changed.

If passwords have not been changed from the default, this is a finding.

Check Content Reference

M

Target Key

3998

Comments