WA000-WI6098 - The MaxRequestEntityAllowed metabase value is not defined - 'IisWebDirectorySetting'

Information

Vulnerability Key: V0013710
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
IIS 6.0 limits the size of requests directly from the settings in the metabase with the metabase entry
MaxRequestEntityAllowed. This entry is similar to the MaxRequest EntityAllowed and
MaxAllowedContentLength settings configured in the UrlScan tool. The MaxRequestEntityAllowed
property specifies the maximum number of bytes allowed in the entity body of a request. If a Content-
Length header is present and specifies an amount of data greater than the value of
MaxRequestEntityAllowed, IIS sends a 403 error response.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Windows

Control ID: 4d691f433878d49dd933f269f4b58f583d36aa878eb51dd9217fa46fd2aa2585