STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

The ScoreBoard file must be properly secured.

DISA Rule

SV-33178r2_rule

Vulnerability Number

V-26322

Group Title

WA00535

Rule Version

WA00535 W22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Modify the location and/or permissions for the ScoreBoard file and/or folder.

Check Contents

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: ScoreBoardFile

If the ScoreBoardFile directive is found uncommented note the directory specified in the directive statement that holds the Scoreboard file. If the ScoreBoardFile directive is not found enabled in the conf file use \logs as the directory containing the Scoreboard file.

If any users other than administrator or the account used to run the web server has permission to the scoreboard file directory, this is a finding. If the ScoreBoard file is located in the web server document root this is finding.

Vulnerability Number

V-26322

Documentable

False

Rule Version

WA00535 W22

Severity Override Guidance

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: ScoreBoardFile

If the ScoreBoardFile directive is found uncommented note the directory specified in the directive statement that holds the Scoreboard file. If the ScoreBoardFile directive is not found enabled in the conf file use \logs as the directory containing the Scoreboard file.

If any users other than administrator or the account used to run the web server has permission to the scoreboard file directory, this is a finding. If the ScoreBoard file is located in the web server document root this is finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments