SV-222593r561254_rule
V-222593
SRG-APP-000435
APSC-DV-002390
CAT II
10
Implement:
- Validation against recursive payloads
- Validation against oversized payloads
- Protection against XML entity expansion
- Validation against overlong element names
- Optimized configuration for maximum message throughput in order to ensure DoS attacks against web services are limited.
Review the application architecture documentation and interview the application administrator to identify what steps have been taken to protect the XML aspect of the application from DoS attacks.
If the application does not contain or utilize XML, the requirement is not applicable.
Ask the application administrator to demonstrate how the application is configured to provide the following protections:
- Validation against recursive payloads
- Validation against oversized payloads
- Protection against XML entity expansion
- Validation against overlong element names
- Optimized configuration for maximum message throughput
If the application administrator cannot demonstrate how these protections are implemented either within the application itself or by third-party tools or utilities like an XML gateway, this is a finding.
V-222593
False
APSC-DV-002390
Review the application architecture documentation and interview the application administrator to identify what steps have been taken to protect the XML aspect of the application from DoS attacks.
If the application does not contain or utilize XML, the requirement is not applicable.
Ask the application administrator to demonstrate how the application is configured to provide the following protections:
- Validation against recursive payloads
- Validation against oversized payloads
- Protection against XML entity expansion
- Validation against overlong element names
- Optimized configuration for maximum message throughput
If the application administrator cannot demonstrate how these protections are implemented either within the application itself or by third-party tools or utilities like an XML gateway, this is a finding.
M
4093