STIGQter STIGQter: STIG Summary: Microsoft IIS 8.5 Site Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

Mappings to unused and vulnerable scripts on the IIS 8.5 website must be removed.

DISA Rule

SV-214455r695296_rule

Vulnerability Number

V-214455

Group Title

SRG-APP-000141-WSR-000082

Rule Version

IISW-SI-000215

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the IIS 8.5 Manager.

Click the site name under review.

Double-click "Request Filtering".

Deny any script file extensions listed on the black list.

Select "Apply" from the "Actions" pane.

Check Contents

For Request Filtering, the ISSO must document and approve all allowable scripts the website allows (white list) and denies (black list). The white list and black list will be compared to the Request Filtering in IIS 8.5.

Open the IIS 8.5 Manager.

Click the site name under review.

Double-click "Request Filtering".

If any script file extensions from the black list are enabled, this is a finding.

Vulnerability Number

V-214455

Documentable

False

Rule Version

IISW-SI-000215

Severity Override Guidance

For Request Filtering, the ISSO must document and approve all allowable scripts the website allows (white list) and denies (black list). The white list and black list will be compared to the Request Filtering in IIS 8.5.

Open the IIS 8.5 Manager.

Click the site name under review.

Double-click "Request Filtering".

If any script file extensions from the black list are enabled, this is a finding.

Check Content Reference

M

Target Key

4001

Comments