Skip to main content
CUI

LAB BASELINES - Findings

Back to Ship Export CSV Download POA&M
Clear Filters Switch to Grouped View
Showing 43 of 43 findings (filtered)
Vuln ID Severity Asset STIG Title Status Doc Status Assigned To Actions
V-218750 CAT I SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Anonymous IIS 10.0 website access accounts must be...
-
V-218768 CAT I SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 private website must employ cryptogra...
-
V-218736 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website session state cookie settings...
-
V-218737 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... A private IIS 10.0 website must only accept Secure...
-
V-218738 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... A public IIS 10.0 website must only accept Secure ...
-
V-218739 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Both the log file and Event Tracing for Windows (E...
-
V-218740 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... An IIS 10.0 website behind a load balancer or prox...
-
V-218741 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must produce log records that...
-
V-218742 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must produce log records cont...
-
V-218743 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must have Multipurpose Intern...
-
V-218744 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Mappings to unused and vulnerable scripts on the I...
-
V-218745 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must have resource mappings s...
-
V-218748 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Each IIS 10.0 website must be assigned a default h...
-
V-218749 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... A private IIS 10.0 website authentication mechanis...
-
V-218751 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must generate unique session ...
-
V-218752 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website document directory must be in...
-
V-218753 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must be configured to limit t...
-
V-218754 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must be configured to limit t...
-
V-218755 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 websites Maximum Query String limit m...
-
V-218756 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Non-ASCII characters in URLs must be prohibited by...
-
V-218757 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Double encoded URL requests must be prohibited by ...
-
V-218758 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Unlisted file extensions in URL requests must be f...
-
V-218759 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Directory Browsing on the IIS 10.0 website must be...
-
V-218760 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Warning and error messages displayed to clients mu...
-
V-218761 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Debugging and trace information used to diagnose t...
-
V-218762 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The Idle Time-out monitor for each IIS 10.0 websit...
-
V-218763 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 websites connectionTimeout setting mu...
-
V-218764 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must provide the capability t...
-
V-218765 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must use a logging mechanism ...
-
V-218766 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 websites must use ports, protocols, a...
-
V-218767 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must only accept client certi...
-
V-218769 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... IIS 10.0 website session IDs must be sent to the c...
-
V-218770 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Cookies exchanged between the IIS 10.0 website and...
-
V-218771 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The IIS 10.0 website must have a unique applicatio...
-
V-218772 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The maximum number of requests an application pool...
-
V-218775 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The application pool for each IIS 10.0 website mus...
-
V-218777 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The application pools rapid fail protection for ea...
-
V-218778 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The application pools rapid fail protection settin...
-
V-218779 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Interactive scripts on the IIS 10.0 web server mus...
-
V-218780 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Interactive scripts on the IIS 10.0 web server mus...
-
V-218781 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... Backup interactive scripts on the IIS 10.0 server ...
-
V-218782 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... The required DoD banner page must be displayed to ...
-
V-278953 CAT II SCHR-P3-DP-001 Microsoft IIS 10.0 Site Security Technic... HTTPAPI Server version must be removed from the HT...
-
CUI