CCI-001312
Generates error messages that provide information necessary for corrective actions without revealing information that could be exploited.
1 rule found Severity: Medium

1 rule found Severity: Medium

The CA API Gateway must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The DataPower Gateway must have ICMP responses disabled on all interfaces facing untrusted networks.
1 rule found Severity: Medium

1 rule found Severity: Medium

DB2 must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The DBMS and associated applications must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

1 rule found Severity: Medium

Nutanix AOS must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

OHS must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
1 rule found Severity: Low

1 rule found Severity: Low

OHS must have the Alias /error directive defined to reference the directory accompanying the ErrorDocument directives to minimize the identity of OHS, patches, loaded modules, and directory paths in warning and error messages displayed to clients.
1 rule found Severity: Medium

OHS must have the permissions set properly via the Directory directive accompanying the ErrorDocument directives to minimize improper access to the warning and error messages displayed to clients.
1 rule found Severity: Medium

OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths.
1 rule found Severity: Low

OHS must have production information removed from error documents to minimize the identity of OHS, patches, loaded modules, and directory paths in warning and error messages displayed to clients.
1 rule found Severity: Low

1 rule found Severity: Medium

1 rule found Severity: Low

Oracle WebLogic must only generate error messages that provide information necessary for corrective actions without revealing sensitive or potentially harmful information in error logs and administrative messages.
1 rule found Severity: Medium

Symantec ProxySG must tailor the Exceptions messages to generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The Ubuntu operating system must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
2 rules found Severity: Medium

MongoDB must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
2 rules found Severity: Medium

The DBMS must only generate error messages that provide information necessary for corrective actions without revealing organization-defined sensitive or potentially harmful information in error logs and administrative messages that could be exploited.
2 rules found Severity: Medium

PostgreSQL must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
2 rules found Severity: Medium

The EDB Postgres Advanced Server must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

IDMS must suppress security-related messages so that no information is returned that can be exploited.
1 rule found Severity: Medium

Custom database code and associated application code must not contain information beyond what is needed for troubleshooting.
1 rule found Severity: Medium

The DBMS must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
2 rules found Severity: Medium

PostgreSQL must provide nonprivileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must provide nonprivileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The Enterprise Voice, Video, and Messaging Session Manager must be configured to generate session (call) records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
1 rule found Severity: Medium

SSMC must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

1 rule found Severity: Medium

MarkLogic Server must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

MongoDB must provide nonprivileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
1 rule found Severity: Medium

1 rule found Severity: Low

1 rule found Severity: Low

Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Automation Controller NGINX web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
1 rule found Severity: Medium

Debugging and trace information, within Automation Controller NGINX web server, used to diagnose the web server must be disabled.
1 rule found Severity: Medium

The SDN controller must be configured to generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

SLEM 5 must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The TPS must block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Tanium application must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
1 rule found Severity: Medium

Warning and error messages displayed to clients must be modified to minimize the identity of the web server, patches, loaded modules, and directory paths.
1 rule found Severity: Medium

1 rule found Severity: Medium

Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
4 rules found Severity: Medium

4 rules found Severity: Medium

The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

The ALG must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The application server must only generate error messages that provide information necessary for corrective actions without revealing sensitive or potentially harmful information in error logs and administrative messages.
1 rule found Severity: Medium

The application must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must generate system journal entries without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must be configured so that the "journalctl" command is not accessible by unauthorized users.
1 rule found Severity: Medium

The container platform must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

Forescout must reveal error messages only to the Information System Security Officer (ISSO), Information System Security Manager (ISSM), and System Administrator (SA). This is required for compliance with C2C Step 1.
1 rule found Severity: Medium

The operating system must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The IDPS must block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Mainframe Product must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

SQL Server must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

Windows Server 2022 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.
1 rule found Severity: High

The Palo Alto Networks security platform must block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
1 rule found Severity: Medium

1 rule found Severity: Medium

The SUSE operating system must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The UEM server must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

The VMM must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium
