STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 26 Apr 2019:

The web server must be configured to use a specified IP address and port.

DISA Rule

SV-54283r3_rule

Vulnerability Number

V-41706

Group Title

SRG-APP-000142-WSR-000089

Rule Version

SRG-APP-000142-WSR-000089

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to only listen on a specified IP address and port.

Check Contents

Review the web server documentation and deployment configuration to determine whether the web server is configured to listen on a specified IP address and port.

Request a client user try to access the web server on any other available IP addresses on the hosting hardware.

If an IP address is not configured on the web server or a client can reach the web server on other IP addresses assigned to the hosting hardware, this is a finding.

Vulnerability Number

V-41706

Documentable

False

Rule Version

SRG-APP-000142-WSR-000089

Severity Override Guidance

Review the web server documentation and deployment configuration to determine whether the web server is configured to listen on a specified IP address and port.

Request a client user try to access the web server on any other available IP addresses on the hosting hardware.

If an IP address is not configured on the web server or a client can reach the web server on other IP addresses assigned to the hosting hardware, this is a finding.

Check Content Reference

M

Target Key

2557

Comments