STIGQter STIGQter: STIG Summary: vRealize - Cassandra Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 05 Jun 2017:

The Cassandra Server must reveal detailed error messages only to the ISSO, ISSM, SA, and DBA.

DISA Rule

SV-87303r1_rule

Vulnerability Number

V-72671

Group Title

SRG-APP-000267-DB-000163

Rule Version

VROM-CS-000200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Cassandra Server to only reveal detailed error messages to the ISSO, ISSM, SA and DBA.

At the command prompt, execute the following command:

# chown admin /usr/lib/vmware-vcops/user/conf/cassandra/<file>

Replace <file> with any file not owned by "admin".

Check Contents

Review the Cassandra Server to ensure detailed error messages are only revealed to the ISSO, ISSM, SA and DBA.

At the command prompt, execute the following command:

# ls -l /usr/lib/vmware-vcops/user/conf/cassandra

If any file is not owned by "admin", this is a finding.

Vulnerability Number

V-72671

Documentable

False

Rule Version

VROM-CS-000200

Severity Override Guidance

Review the Cassandra Server to ensure detailed error messages are only revealed to the ISSO, ISSM, SA and DBA.

At the command prompt, execute the following command:

# ls -l /usr/lib/vmware-vcops/user/conf/cassandra

If any file is not owned by "admin", this is a finding.

Check Content Reference

M

Target Key

3179

Comments