Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35099 | SRG-APP-000298-AS-NA | SV-46386r1_rule | Medium |
Description |
---|
Decisions regarding the utilization of mobile code within organizational information systems needs to include evaluations which help determine the potential for the code to cause damage to the system if used maliciously. Mobile code technologies include, for example, Java, JavaScript, ActiveX, PDF, Postscript, Shockwave movies, Flash animations, and VBScript. The requirement is NA. The AS may host applications that utilize or offer mobile code but it does not enforce mobile code policies. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43487r1_chk ) |
---|
This requirement is NA for the AS SRG. |
Fix Text (F-39651r1_fix) |
---|
The application must prevent the execution of prohibited mobile code. |