9.9 Secure plug-in library locations - group

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If plug-in directories are not secure, the plug-ins could be misused, tampered with, or otherwise accessed in ways that could jeopardize the security of the server.

Solution

hange the privileges for all plug-in directories so they are set to 755.

On a Linux system, perform the following for each directory needing its privileges changed:
[db2inst1@tgt-db2-101-abc123 IBM]$ chmod 755 <directory>

See Also

https://workbench.cisecurity.org/files/162

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 4f56d1843d6d746753ed71d0fcf8fbafc56bab04c33a7fe40b15873ba0ebca62