WA00535 W22 - The ScoreBoard file must be properly secured.

Information

The ScoreBoardFile directive sets a file path which the server will use for Inter-Process Communication (IPC) among the Apache processes. If the directive is specified, then Apache will use the configured file for the inter-process communication. Therefore if it is specified it needs to be located in a secure directory. If the ScoreBoard file is placed in openly writable directory, other accounts could create a denial of service attack and prevent the server from starting by creating a file with the same name, and or users could monitor and disrupt the communication between the processes by reading and writing to the file.

Solution

Modify the location and/or permissions for the ScoreBoard file and/or folder.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_WIN_V1R12_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6, 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-33178r1_rule, STIG-ID|WA00535, Vuln-ID|V-26322

Plugin: Windows

Control ID: fe4949cf3e35ba30b5b6296187c03653a183eb58abd0c3e96b401dccd80475d3