STIGQter STIGQter: STIG Summary: Oracle WebLogic Server 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

Oracle WebLogic must fail securely in the event of an operational failure.

DISA Rule

SV-235991r628751_rule

Vulnerability Number

V-235991

Group Title

SRG-APP-000225-AS-000166

Rule Version

WBLC-08-000238

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Access AC
2. From 'Domain Structure', select 'Environment' -> 'Servers'
3. From the list of servers, select one which is assigned a protocol which does not end in 's' (secure)
4. Utilize 'Change Center' to create a new change session
5. From 'Configuration' tab -> 'General' tab, deselect the 'Listen Port Enabled' checkbox
6. Select the 'SSL Listen Port Enabled checkbox
7. Enter a valid port value in the 'SSL Listen Port' field and click 'Save'
8. Review the 'Port Usage' table in EM again to ensure all values in the 'Protocol' column end with 's' (secure)

Check Contents

1. Access EM
2. Select the domain from the navigation tree, and use the dropdown to select 'WebLogic Domain' -> 'Monitoring' -> 'Port Usage'
3. In the results table, ensure values in the 'Protocol' column each end with 's' (secure)

If the protocols are not secure, this is a finding.

Vulnerability Number

V-235991

Documentable

False

Rule Version

WBLC-08-000238

Severity Override Guidance

1. Access EM
2. Select the domain from the navigation tree, and use the dropdown to select 'WebLogic Domain' -> 'Monitoring' -> 'Port Usage'
3. In the results table, ensure values in the 'Protocol' column each end with 's' (secure)

If the protocols are not secure, this is a finding.

Check Content Reference

M

Target Key

5282

Comments