WA000-WI6086 - The MaxFieldLength registry entry is not set properly.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Vulnerability Key: V0013717
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
By default, the MaxFieldLength registry entry is not present. This registry entry specifies the maximum size of any individual
HTTP client request. Typically, this registry entry is configured together with the MaxRequestBytes registry entry. Setting this
value to high, when the application does not require it to operate, may cause performance problems as well as denial of service
issues for the web server.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Windows

Control ID: 8b1e6f8edd44d25f6e2041d37364a24aed1ffad792dbd1428697da7aa76d7fd9