UCF STIG Viewer Logo

The DBMS must restrict error messages, so only authorized personnel may view them.


Overview

Finding ID Version Rule ID IA Controls Severity
V-32571 SRG-APP-000267-DB-000163 SV-42908r1_rule Medium
Description
If the application provides too much information in error logs and administrative messages to the screen, this could lead to compromise. The structure and content of error messages need to be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements. Some default DBMS error messages can contain information that could aid an attacker in, among others things, identifying the database type, host address, or state of the database. Custom errors may contain sensitive customer information. It is important that error messages are displayed only to those who are authorized to view them.
STIG Date
Database Security Requirements Guide 2012-07-02

Details

Check Text ( C-41010r1_chk )
Check DBMS settings and custom database code to determine if error messages are ever displayed to unauthorized individuals. If error messages are displayed to individuals not authorized to view them, this is a finding.
Fix Text (F-36486r1_fix)
Configure DBMS and custom database code to not display error messages to those not authorized to view them.