WA150 - Web applications or servers, do not require web users to have a user ID and password that provide access only to the web content.

Information

Vulnerability Key: V0013615
IA Controls: IAIA-1 Individual Identification and Authentication, IAIA-2 Individual Identification and Authentication
Categories: 1.3 Identity Management
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.6
Some web-based applications utilize the use of user IDs and passwords. In some cases these
passwords are OS accounts and provide remote user access to other applications or databases. In this
situation, the OS password policy applies. In other instances, the user ID and password scheme is
determined by the application. In this case, the application's documentation should detail the policy to
be followed to add users and select or change passwords. In cases where a Lightweight Directory
Access Protocol (LDAP) server is used for authentication, the procedures for the web server suite
should detail the web site's password policy. A process for changing the forgotten password should be
followed. Password policies to include password strength will comply with the appropriate operating
system STIG.'as it requires manual verification with the IAO, SA, and/or Web Manager that all scripts
are reviewed by a CCB or technical group prior to their installation on the web server.
NOTE: Nessus did not perform this check as it requires manual verification with the IAO, SA, Web Manager, Webmaster or developers
to detemine if user ID and passwords are required to access web content and how they are configured on the
system.