UCF STIG Viewer Logo

The application server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35304 SRG-APP-000156-AS-000106 SV-46591r1_rule High
Description
Application servers may provide a web services capability that could be leveraged to allow remote access to sensitive application data. A web service, which is a repeatable process used to make data available to remote clients, should not be confused with a web server. Many web services utilize SOAP which in turn utilizes XML and HTTP as a transport. Natively, SOAP does not provide security protections. As such, the application server must provide security extensions to enhance SOAP capabilities so as to ensure that secure authentication mechanisms are employed to protect sensitive data. The WS_Security suite is a widely used and acceptable SOAP security extension.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43673r1_chk )
Review AS documentation to ensure the AS provides extensions to the SOAP protocol that provide secure authentication. Review policy and data owner protection requirements in order to identify sensitive data. If secure authentication protocols are not utilized to protect data identified by data owner as requiring protection, this is a finding.
Fix Text (F-39850r1_fix)
Configure the AS to utilize secure authentication when SOAP web services are used to access sensitive data.