Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-28170 | SHPT-00-000480 | SV-37769r2_rule | Medium |
Description |
---|
During the installation of Microsoft SharePoint, the Central Administration Web site is established on a randomly-assigned TCP port by default. Allowing a randomly-assigned default may result in use of a port which violates DoD policy or conflicts with ports already in use. Use of certain well-known ports may also result in slow operational responses or may expose the application to denial of service attacks. |
STIG | Date |
---|---|
MS SharePoint 2010 Security Technical Implementation Guide | 2018-04-02 |
Check Text ( C-36997r4_chk ) |
---|
1. In Central Administrator, view the URL in the address bar of the browser. 2. The URL includes a colon which is followed by the port number. 3. Mark as a finding if the port number used is not allowed in accordance with DoD PPSM policy or is less than 1024. |
Fix Text (F-32261r3_fix) |
---|
1. Open the SharePoint 2010 Management Shell (Start > All Programs > Microsoft SharePoint 2010 Products > SharePoint 2010 Management Shell). 2. Change the port number to a PPSM approved port which does not conflict with existing port usage by using the following command: –Set -SPCentralAdministration -Port 3. Press Enter to save. |