UCF STIG Viewer Logo

The WebSphere Application Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.


Overview

Finding ID Version Rule ID IA Controls Severity
V-81293 WBSP-AS-000980 SV-96007r1_rule Medium
Description
Some networking protocols may not meet organizational security requirements to protect data and components. Application servers natively host a number of various features, such as management interfaces, httpd servers, and message queues. These features all run on TCPIP ports. This creates the potential that the vendor may choose to utilize port numbers or network services that have been deemed unusable by the organization. The application server must have the capability to both reconfigure and disable the assigned ports without adversely impacting application server operation capabilities. For a list of approved ports and protocols, reference the DoD ports and protocols website at https://powhatan.iiie.disa.mil/ports/cal.html.
STIG Date
IBM WebSphere Traditional V9.x Security Technical Implementation Guide 2018-08-24

Details

Check Text ( C-80991r2_chk )
In the administrative console, click Servers >> All Servers.

Select each [server_name].

Select >> Ports.

Confirm server ports are registered with PPSM.

Navigate to System Administration >> Deployment Manager >> Ports.

Confirm ports are registered with PPSM.

Navigate to System Administration >> node agents.

For each [node agent], select >> Ports.

Confirm ports are registered with PPSM.

If any of available ports are not registered with PPSM, or if those ports to be connected through the firewall are not approved by PPSM, this is a finding.
Fix Text (F-88075r1_fix)
Ensure all available ports are registered with PPSM.