SV-222443r508029_rule
V-222443
SRG-APP-000089
APSC-DV-000640
CAT II
10
Design or reconfigure the application to log session renewal events on those application events that provide changes in the users privileges or permissions to the application.
Interview the system admin and review the application documentation.
Identify any web pages or application functionality where a user's privileges or permissions will change. This is most likely to occur during the authentication stages.
Evaluate the log/audit output by opening the log files and observing changes to the logs.
Create a new user session by accessing the application.
Review the logs and save the relevant session creation event recorded.
Utilize the application pages that provide privilege escalation.
Escalate privileges by authenticating as a privileged user.
Review the logs and determine if new session information is created and being used.
If a web-based application delegates session ID renewals to an application server, this is not a finding.
If the application is not configured to log session ID renewal events this is a finding.
V-222443
False
APSC-DV-000640
Interview the system admin and review the application documentation.
Identify any web pages or application functionality where a user's privileges or permissions will change. This is most likely to occur during the authentication stages.
Evaluate the log/audit output by opening the log files and observing changes to the logs.
Create a new user session by accessing the application.
Review the logs and save the relevant session creation event recorded.
Utilize the application pages that provide privilege escalation.
Escalate privileges by authenticating as a privileged user.
Review the logs and determine if new session information is created and being used.
If a web-based application delegates session ID renewals to an application server, this is not a finding.
If the application is not configured to log session ID renewal events this is a finding.
M
4093