SV-32980r3_rule
V-13724
WA000-WWA020
WA000-WWA020 W22
CAT II
10
Modify the Timeout directive in the applicable Apache configuration files to have a value of 300 seconds or less.
NOTE: This setting must be explicitly set.
Locate the Apache httpd.conf file.
Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: Timeout
Every enabled Timeout directive value needs to be 300 or less. If any directive is set improperly, this is a finding.
NOTE: This vulnerability can be documented locally with the ISSM/ISSO if the site has an operational reason for the use of an increased value. If the site has this documented, this should be marked as Not a Finding.
V-13724
False
WA000-WWA020 W22
NOTE: This setting must be explicitly set.
Locate the Apache httpd.conf file.
Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: Timeout
Every enabled Timeout directive value needs to be 300 or less. If any directive is set improperly, this is a finding.
NOTE: This vulnerability can be documented locally with the ISSM/ISSO if the site has an operational reason for the use of an increased value. If the site has this documented, this should be marked as Not a Finding.
M
Web Administrator
158