Skip to content

IBM WebSphere Liberty Server Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Application security must be enabled on the WebSphere Liberty Server.

    <VulnDiscussion>Application security enables security for the applications in the environment. This type of security provides application iso...
    Rule High Severity
  • SRG-APP-000340-AS-000185

    <GroupDescription></GroupDescription>
    Group
  • Users in a reader-role must be authorized.

    &lt;VulnDiscussion&gt;The reader role is a management role that allows read-only access to select administrative REST APIs as well as the Admin Cen...
    Rule Medium Severity
  • SRG-APP-000357-AS-000038

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.

    &lt;VulnDiscussion&gt;JVM logs are logs used to store application and runtime related events, rather than audit related events. They are mainly use...
    Rule Medium Severity
  • SRG-APP-000380-AS-000088

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must prohibit the use of cached authenticators after an organization-defined time period.

    &lt;VulnDiscussion&gt;Larger authentication cache timeout values can increase security risks. For example, a user who is revoked can still log in b...
    Rule Medium Severity
  • SRG-APP-000428-AS-000265

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server LTPA keys password must be changed.

    &lt;VulnDiscussion&gt;The default location of the automatically generated Lightweight Third Party Authentication (LTPA) keys file is ${server.outpu...
    Rule Medium Severity
  • SRG-APP-000439-AS-000274

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.

    &lt;VulnDiscussion&gt;Export grade encryption suites are not strong and do not meet DoD requirements. The encryption for the session becomes easy f...
    Rule Medium Severity
  • SRG-APP-000440-AS-000167

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must be configured to use HTTPS only.

    &lt;VulnDiscussion&gt;Transmission of data can take place between the application server and a large number of devices/applications external to the...
    Rule Medium Severity
  • SRG-APP-000456-AS-000266

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must install security-relevant software updates within the time period directed by an authoritative source.

    &lt;VulnDiscussion&gt;Security vulnerabilities are often addressed by testing and applying the latest security patches and fix packs. The latest fi...
    Rule Medium Severity
  • SRG-APP-000499-AS-000224

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules