Finding ID |
Severity |
Title |
Description |
V-224549
|
High |
Vendor-supplied user accounts for the WebSphere Application Server must be defined to the ACP. |
Vendor-supplied user accounts are defined to the ACP with factory-set passwords during the installation of the WebSphere Application Server (WAS). These user accounts are common to all WAS environments and have access to restricted resources and functions. Failure to delete vendor-supplied user accounts from the ACP may lead to unauthorized... |
V-224550
|
Medium |
The WebSphere Application Server plug-in is not specified in accordance with the proper security requirements. |
Requests processed by the WebSphere Application Server (WAS) are dependent on directives configured in the HTTP server httpd.conf file. These directives specify critical files containing the WAS plug-in and WAS configuration. These files provide the operational and security characteristics of WAS. Failure to properly configure WAS-related directives could lead to... |
V-224548
|
Medium |
The CBIND Resource Class for the WebSphere Application Server is not configured in accordance with security requirements.
|
SAF resources provide the ability to control access to functions and services of the WebSphere Application Server (WAS) environment. Many of these resources provide operational and administrative support for WAS. Failure to properly protect these resources may lead to unauthorized access. This exposure could compromise the integrity and availability of... |
V-224547
|
Medium |
HFS objects for the WebSphere Application Server are not protected in accordance with the proper security requirements. |
HFS directories and files provide the configuration, operational, and executable properties of the WebSphere Application Server (WAS) environment. Many of these objects are responsible for the security implementation of WAS. Failure to properly protect these directories and files may lead to unauthorized access. This exposure could potentially compromise the integrity... |
V-224546
|
Medium |
MVS data sets for the WebSphere Application Server are not protected in accordance with the proper security requirements. |
MVS data sets provide the configuration, operational, and executable properties of the WebSphere Application Server (WAS) environment. Failure to properly protect these data sets may lead to unauthorized access. This exposure could compromise the integrity and availability of system services, applications, and customer data. |