Item Search

NameAudit NamePluginCategory
EP11-00-006200 - The EDB Postgres Advanced Server must check the validity of all data inputs except those specifically identified by the organization.EDB PostgreSQL Advanced Server v11 DB Audit v2r2PostgreSQLDB
EP11-00-006200 - The EDB Postgres Advanced Server must check the validity of all data inputs except those specifically identified by the organization.EDB PostgreSQL Advanced Server v11 DB Audit v2r3PostgreSQLDB
EP11-00-006300 - The EDB Postgres Advanced Server and associated applications must reserve the use of dynamic code execution for situations that require it.EDB PostgreSQL Advanced Server v11 DB Audit v2r3PostgreSQLDB
EP11-00-006300 - The EDB Postgres Advanced Server and associated applications must reserve the use of dynamic code execution for situations that require it.EDB PostgreSQL Advanced Server v11 DB Audit v2r2PostgreSQLDB
EP11-00-006400 - The EDB Postgres Advanced Server and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.EDB PostgreSQL Advanced Server v11 DB Audit v2r3PostgreSQLDB
EP11-00-006400 - The EDB Postgres Advanced Server and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.EDB PostgreSQL Advanced Server v11 DB Audit v2r2PostgreSQLDB
F5BI-AS-000261 - The BIG-IP ASM module must check the validity of all data inputs except those specifically identified by the organization.DISA F5 BIG-IP Application Security Manager 11.x STIG v1r1F5

SYSTEM AND INFORMATION INTEGRITY

F5BI-LT-000261 - The BIG-IP Core implementation must be configured to check the validity of all data inputs except those specifically identified by the organization.DISA F5 BIG-IP Local Traffic Manager 11.x STIG v1r3F5

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-LT-000261 - The BIG-IP Core implementation must be configured to check the validity of all data inputs except those specifically identified by the organization.DISA F5 BIG-IP Local Traffic Manager 11.x STIG v2r2F5
IIST-SI-000231 - Directory Browsing on the IIS 10.0 website must be disabled.DISA IIS 10.0 Site v2r5Windows
IIST-SI-000231 - Directory Browsing on the IIS 10.0 website must be disabled.DISA IIS 10.0 Site v2r7Windows
IIST-SI-000231 - Directory Browsing on the IIS 10.0 website must be disabled.DISA IIS 10.0 Site v2r8Windows
IIST-SV-000138 - Directory Browsing on the IIS 10.0 web server must be disabled.DISA IIS 10.0 Server v2r8Windows
IIST-SV-000138 - Directory Browsing on the IIS 10.0 web server must be disabled.DISA IIS 10.0 Server v2r9Windows
IIST-SV-000138 - Directory Browsing on the IIS 10.0 web server must be disabled.DISA IIS 10.0 Server v2r5Windows
IISW-SI-000231 - Directory Browsing on the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v1r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000231 - Directory Browsing on the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v2r5Windows
IISW-SI-000231 - Directory Browsing on the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v2r7Windows
IISW-SI-000231 - Directory Browsing on the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v2r8Windows
IISW-SV-000138 - Directory Browsing on the IIS 8.5 web server must be disabled.DISA IIS 8.5 Server v1r9Windows

CONFIGURATION MANAGEMENT

IISW-SV-000138 - Directory Browsing on the IIS 8.5 web server must be disabled.DISA IIS 8.5 Server v2r3Windows
IISW-SV-000138 - Directory Browsing on the IIS 8.5 web server must be disabled.DISA IIS 8.5 Server v2r6Windows
IISW-SV-000138 - Directory Browsing on the IIS 8.5 web server must be disabled.DISA IIS 8.5 Server v2r5Windows
MD3X-00-000490 - MongoDB must check the validity of all data inputs except those specifically identified by the organization.DISA STIG MongoDB Enterprise Advanced 3.x v2r2 OSUnix
MD3X-00-000490 - MongoDB must check the validity of all data inputs except those specifically identified by the organization.DISA STIG MongoDB Enterprise Advanced 3.x v2r1 OSUnix
MD3X-00-000500 - MongoDB and associated applications must reserve the use of dynamic code execution for situations that require it.DISA STIG MongoDB Enterprise Advanced 3.x v2r1 OSUnix
MD3X-00-000500 - MongoDB and associated applications must reserve the use of dynamic code execution for situations that require it.DISA STIG MongoDB Enterprise Advanced 3.x v2r2 OSUnix
O112-C2-019500 - The DBMS must check the validity of data inputs.DISA STIG Oracle 11.2g v2r4 DatabaseOracleDB
O112-C2-019500 - The DBMS must check the validity of data inputs.DISA STIG Oracle 11.2g v2r3 DatabaseOracleDB
O121-C2-019500 - The DBMS must check the validity of data inputs.DISA STIG Oracle 12c v2r6 DatabaseOracleDB
O121-C2-019500 - The DBMS must check the validity of data inputs.DISA STIG Oracle 12c v2r9 DatabaseOracleDB
O121-C2-019500 - The DBMS must check the validity of data inputs.DISA STIG Oracle 12c v2r8 DatabaseOracleDB
PGS9-00-001800 - PostgreSQL must check the validity of all data inputs except those specifically identified by the organization.DISA STIG PostgreSQL 9.x on RHEL DB v2r4PostgreSQLDB
PGS9-00-001800 - PostgreSQL must check the validity of all data inputs except those specifically identified by the organization.DISA STIG PostgreSQL 9.x on RHEL DB v2r3PostgreSQLDB
PGS9-00-001900 - PostgreSQL and associated applications must reserve the use of dynamic code execution for situations that require it.DISA STIG PostgreSQL 9.x on RHEL DB v2r3PostgreSQLDB
PGS9-00-001900 - PostgreSQL and associated applications must reserve the use of dynamic code execution for situations that require it.DISA STIG PostgreSQL 9.x on RHEL DB v2r4PostgreSQLDB
PGS9-00-002000 - PostgreSQL and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.DISA STIG PostgreSQL 9.x on RHEL DB v2r3PostgreSQLDB
PGS9-00-002000 - PostgreSQL and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.DISA STIG PostgreSQL 9.x on RHEL DB v2r4PostgreSQLDB
PPS9-00-006200 - The EDB Postgres Advanced Server must check the validity of all data inputs except those specifically identified by the organization.EDB PostgreSQL Advanced Server DB Audit v2r2PostgreSQLDB
PPS9-00-006300 - The EDB Postgres Advanced Server and associated applications must reserve the use of dynamic code execution for situations that require it.EDB PostgreSQL Advanced Server DB Audit v2r2PostgreSQLDB
PPS9-00-006400 - The EDB Postgres Advanced Server and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.EDB PostgreSQL Advanced Server DB Audit v2r2PostgreSQLDB
SQL6-D0-002100 - SQL Server must check the validity of all data inputs except those specifically identified by the organization.DISA STIG SQL Server 2016 Database Audit v2r8MS_SQLDB
SQL6-D0-002100 - SQL Server must check the validity of all data inputs except those specifically identified by the organization.DISA STIG SQL Server 2016 Database Audit v2r5MS_SQLDB
SQL6-D0-002100 - SQL Server must check the validity of all data inputs except those specifically identified by the organization.DISA STIG SQL Server 2016 Database Audit v2r6MS_SQLDB
SQL6-D0-002100 - SQL Server must check the validity of all data inputs except those specifically identified by the organization.DISA STIG SQL Server 2016 Database Audit v2r9MS_SQLDB
VCLD-70-000019 - VAMI must set the encoding for all text Multipurpose Internet Mail Extensions (MIME) types to UTF-8 - erbDISA STIG VMware vSphere 7.0 VAMI v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

WDNS-SI-000001 - The Windows 2012 DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, to include IP ranges and IP versions.DISA Microsoft Windows 2012 Server DNS STIG v2r4Windows
WDNS-SI-000001 - The Windows 2012 DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, to include IP ranges and IP versions.DISA Microsoft Windows 2012 Server DNS STIG v2r5Windows
WDNS-SI-000001 - The Windows 2012 DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, to include IP ranges and IP versions.DISA Microsoft Windows 2012 Server DNS STIG v2r1Windows
WDNS-SI-000001 - The Windows 2012 DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, to include IP ranges and IP versions.DISA Microsoft Windows 2012 Server DNS STIG v2r6Windows