STIGQter STIGQter: STIG Summary: Solaris 10 X86 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

The limitpriv zone option must be set to the vendor default or less permissive.

DISA Rule

SV-227554r603266_rule

Vulnerability Number

V-227554

Group Title

SRG-OS-000480

Rule Version

GEN000000-SOL00640

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the limitpriv setting to default.
# zonecfg -z <zone> set limitpriv=default

Check Contents

If the system is not a global zone, this vulnerability is not applicable.
List the non-global zones on the system.
# zoneadm list -vi
List the configuration for each zone.
# zonecfg -z <zone> info
Check the limitpriv lines. If a line set other than default, this is a finding. If limitpriv is not set, this is not a finding.

Vulnerability Number

V-227554

Documentable

False

Rule Version

GEN000000-SOL00640

Severity Override Guidance

If the system is not a global zone, this vulnerability is not applicable.
List the non-global zones on the system.
# zoneadm list -vi
List the configuration for each zone.
# zonecfg -z <zone> info
Check the limitpriv lines. If a line set other than default, this is a finding. If limitpriv is not set, this is not a finding.

Check Content Reference

M

Target Key

4061

Comments