Check: SRG-APP-000133-AS-000092
Application Server SRG:
SRG-APP-000133-AS-000092
(in versions v3 r4 through v2 r2)
Title
The application server must limit privileges to change the software resident within software libraries. (Cat II impact)
Discussion
Application servers have the ability to specify that the hosted applications utilize shared libraries. The application server must have a capability to divide roles based upon duties wherein one project user (such as a developer) cannot modify the shared library code of another project user. The application server must also be able to specify that non-privileged users cannot modify any shared library code at all.
Check Content
Check the application server documentation and configuration to determine if the application server provides role-based access that limits the capability to change shared software libraries. Validate file permission settings to ensure library files are secured in relation to OS access. If the application server does not meet this requirement, this is a finding.
Fix Text
Configure the application server to limit privileges to change the software resident within software libraries through the use of defined user roles and file permissions.
Additional Identifiers
Rule ID: SV-204741r879586_rule
Vulnerability ID: V-204741
Group Title: SRG-APP-000133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001499 |
The organization limits privileges to change software resident within software libraries. |
Controls
Number | Title |
---|---|
CM-5 (6) |
Limit Library Privileges |