Skip to content

The ALG must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.

An XCCDF Rule

Description

<VulnDiscussion>Providing too much information in error messages risks compromising the data and security of the application and system. Organizations carefully consider the structure/content of error messages. The required information within error messages will vary based on the protocol and error condition. Information that could be exploited by adversaries includes, for example, ICMP messages that reveal the use of firewalls or access-control lists.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-204969r396042_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Configure the ALG to generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.