STIGQter STIGQter: STIG Summary: Oracle WebLogic Server 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

Oracle WebLogic must protect the integrity and availability of publicly available information and applications.

DISA Rule

SV-235982r628724_rule

Vulnerability Number

V-235982

Group Title

SRG-APP-000435-AS-000069

Rule Version

WBLC-08-000218

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Access AC
2. From 'Domain Structure', select 'Deployments'
3. Select a deployed component which contains publicly available information and/or applications
4. Utilize 'Change Center' to create a new change session
5. Select 'Targets' tab
6. Select one or more clusters of managed servers as a target for this deployment. Click 'Save'.

Check Contents

1. Access AC
2. From 'Domain Structure', select 'Deployments'
3. Select a deployed component which contains publicly available information and/or applications
4. Select 'Targets' tab
5. Ensure one or more of the selected targets for this deployment is a cluster of managed servers

If the information requires clustering of managed server and the managed servers are not clustered, this is a finding.

Vulnerability Number

V-235982

Documentable

False

Rule Version

WBLC-08-000218

Severity Override Guidance

1. Access AC
2. From 'Domain Structure', select 'Deployments'
3. Select a deployed component which contains publicly available information and/or applications
4. Select 'Targets' tab
5. Ensure one or more of the selected targets for this deployment is a cluster of managed servers

If the information requires clustering of managed server and the managed servers are not clustered, this is a finding.

Check Content Reference

M

Target Key

5282

Comments