AS24-U1-000960 - The Apache web server software must be a vendor-supported version.

Information

Many vulnerabilities are associated with older versions of web server software. As hot fixes and patches are issued, these solutions are included in the next version of the server software. Maintaining the web server at a current version makes the efforts of a malicious user to exploit the web service more difficult.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Install the current version of the web server software and maintain appropriate service packs and patches.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Server_2-4_Unix_Y24M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-214273r961863_rule, STIG-ID|AS24-U1-000960, STIG-Legacy|SV-102843, STIG-Legacy|V-92755, Vuln-ID|V-214273

Plugin: Unix

Control ID: 08edfe9805f7ae26d5ae6658230e4d2aadeb0767c00ccbd82edb5a4fc45788b9