Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-239524 | VROM-SL-000525 | SV-239524r662023_rule | Medium |
Description |
---|
Implementing NIS or NIS+ under UDP may make SLES for vRealize more susceptible to a denial of service attack and does not provide the same quality of service as TCP. |
STIG | Date |
---|---|
VMware vRealize Operations Manager 6.x SLES Security Technical Implementation Guide | 2021-07-01 |
Check Text ( C-42757r662021_chk ) |
---|
If SLES for vRealize does not use NIS or NIS+, this is not applicable. Check if NIS or NIS+ is implemented using UDP: # rpcinfo -p | grep yp | grep udp If NIS or NIS+ is implemented using UDP, this is a finding. |
Fix Text (F-42716r662022_fix) |
---|
Configure SLES for vRealize to not use UDP for NIS and NIS+. Consult vendor documentation for the required procedure. |