SV-81887r2_rule
V-67397
SRG-APP-000266-DB-000162
SQL4-00-022800
CAT II
10
Configure DBMS settings, custom database code, and associated application code not to divulge sensitive information or information useful for system identification in error messages that are displayed to general users.
Review application behavior and custom database code (stored procedures; triggers), to determine whether error messages contain information beyond what is needed for explaining the issue to general users.
If database error messages contain PII data, sensitive business data, or information useful for identifying the host system or database structure, this is a finding.
V-67397
False
SQL4-00-022800
Review application behavior and custom database code (stored procedures; triggers), to determine whether error messages contain information beyond what is needed for explaining the issue to general users.
If database error messages contain PII data, sensitive business data, or information useful for identifying the host system or database structure, this is a finding.
M
2637