SV-77025r1_rule
V-62535
SRG-APP-000267-AS-000170
CF11-06-000222
CAT II
10
Navigate to the "User Manager" page under the "Security" menu. Remove the "Debugging and Logging>Logging" role from each user that should not have access to read error messages.
Within the Administrator Console, navigate to the "User Manager" page under the "Security" menu. Review each defined user and ask the SA if the user should have access to read error messages. For each user that should not be able to read error messages, review the roles assigned to the user account.
If any user has the Debugging and Logging>Logging role that should not be able to read error messages, this is a finding.
V-62535
False
CF11-06-000222
Within the Administrator Console, navigate to the "User Manager" page under the "Security" menu. Review each defined user and ask the SA if the user should have access to read error messages. For each user that should not be able to read error messages, review the roles assigned to the user account.
If any user has the Debugging and Logging>Logging role that should not be able to read error messages, this is a finding.
M
2661