Skip to content

The application must not contain embedded authentication data.

An XCCDF Rule

Description

Authentication data stored in code could potentially be read and used by anonymous users to gain access to a backend database or application servers. This could lead to compromise of application data.

ID
SV-222642r961863_rule
Version
APSC-DV-003110
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

Remove embedded authentication data stored in code, configuration files, scripts, HTML file, or any ASCII files.