STIGQter STIGQter: STIG Summary: IBM DB2 V10.5 LUW Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 25 Oct 2019:

DB2 must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.

DISA Rule

SV-89189r1_rule

Vulnerability Number

V-74515

Group Title

SRG-APP-000266-DB-000162

Rule Version

DB2X-00-006200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DB2 settings, custom database code, and associated application code not to divulge sensitive information or information useful for system identification in error messages.

Check Contents

Check DB2 settings and custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.

If database errors contain PII data, sensitive business data, or information useful for identifying the host system or database structure, this is a finding.

Vulnerability Number

V-74515

Documentable

False

Rule Version

DB2X-00-006200

Severity Override Guidance

Check DB2 settings and custom database code to verify that error messages do not contain information beyond what is needed for troubleshooting the issue.

If database errors contain PII data, sensitive business data, or information useful for identifying the host system or database structure, this is a finding.

Check Content Reference

M

Target Key

3161

Comments