Skip to content

Unnecessary built-in application accounts must be disabled.

An XCCDF Rule

Description

Default passwords and properties of built-in accounts are often publicly available. Anyone with necessary knowledge, internal or external, can compromise an application using built-in accounts. Built-in accounts are those that are added as part of the installation of the application software. These accounts exist for many common Commercial Off-the-Shelf (COTS) or open source components of enterprise applications (e.g., OS, web browser or database software).

ID
SV-222661r961863_rule
Version
APSC-DV-003270
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Disable unnecessary built-in userids, use other strong authentication when possible and use strong passwords if accounts are necessary for application operation.