Check: GEN003810
SUSE Linux Enterprise Server v11 for System z STIG:
GEN003810
(in versions v1 r12 through v1 r9)
Title
The portmap or rpcbind service must not be running unless needed. (Cat II impact)
Discussion
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
Check Content
Check the status of the portmap and/or rpcbind service. # rcportmap status # rcrpcbind status If the service is running, this is a finding.
Fix Text
Shutdown and disable the portmap and/or rpcbind service. # rcportmap stop; insserv –r portmap # rcrpcbind stop; insserv –r rpcbind
Additional Identifiers
Rule ID: SV-45785r1_rule
Vulnerability ID: V-22429
Group Title: GEN003810
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001336 |
The organization retains individual training records for an organization-defined time period. |
Controls
Number | Title |
---|---|
AT-4 |
Security Training Records |