Unnecessary built-in application accounts must be disabled.
An XCCDF Rule
Description
Default passwords and properties of built-in accounts are often publicly available. Anyone with necessary knowledge, internal or external, can compromise an application using built-in accounts. Built-in accounts are those that are added as part of the installation of the application software. These accounts exist for many common Commercial Off-the-Shelf (COTS) or open source components of enterprise applications (e.g., OS, web browser or database software).
- ID
- SV-222661r961863_rule
- Version
- APSC-DV-003270
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Disable unnecessary built-in userids, use other strong authentication when possible and use strong passwords if accounts are necessary for application operation.