Skip to main content
CUI

LAB BASELINES - Findings

Back to Ship Export CSV Download POA&M
Clear Filters Switch to Flat View
Showing 43 unique vulnerabilities (43 total) (filtered)
V-218750 CAT I Anonymous IIS 10.0 website access accounts must be restricte...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218768 CAT I The IIS 10.0 private website must employ cryptographic mecha...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218736 CAT II The IIS 10.0 website session state cookie settings must be c...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218737 CAT II A private IIS 10.0 website must only accept Secure Socket La...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218738 CAT II A public IIS 10.0 website must only accept Secure Socket Lay...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218739 CAT II Both the log file and Event Tracing for Windows (ETW) for ea...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218740 CAT II An IIS 10.0 website behind a load balancer or proxy server m...
1 asset Microsoft IIS 10.0 S...
V-218741 CAT II The IIS 10.0 website must produce log records that contain s...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218742 CAT II The IIS 10.0 website must produce log records containing suf...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218743 CAT II The IIS 10.0 website must have Multipurpose Internet Mail Ex...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218744 CAT II Mappings to unused and vulnerable scripts on the IIS 10.0 we...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218745 CAT II The IIS 10.0 website must have resource mappings set to disa...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218748 CAT II Each IIS 10.0 website must be assigned a default host header...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218749 CAT II A private IIS 10.0 website authentication mechanism must use...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218751 CAT II The IIS 10.0 website must generate unique session identifier...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218752 CAT II The IIS 10.0 website document directory must be in a separat...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218753 CAT II The IIS 10.0 website must be configured to limit the maxURL.
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218754 CAT II The IIS 10.0 website must be configured to limit the size of...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218755 CAT II The IIS 10.0 websites Maximum Query String limit must be con...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218756 CAT II Non-ASCII characters in URLs must be prohibited by any IIS 1...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218757 CAT II Double encoded URL requests must be prohibited by any IIS 10...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218758 CAT II Unlisted file extensions in URL requests must be filtered by...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218759 CAT II Directory Browsing on the IIS 10.0 website must be disabled.
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218760 CAT II Warning and error messages displayed to clients must be modi...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218761 CAT II Debugging and trace information used to diagnose the IIS 10....
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218762 CAT II The Idle Time-out monitor for each IIS 10.0 website must be ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218763 CAT II The IIS 10.0 websites connectionTimeout setting must be expl...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218764 CAT II The IIS 10.0 website must provide the capability to immediat...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218765 CAT II The IIS 10.0 website must use a logging mechanism configured...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218766 CAT II The IIS 10.0 websites must use ports, protocols, and service...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218767 CAT II The IIS 10.0 website must only accept client certificates is...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218769 CAT II IIS 10.0 website session IDs must be sent to the client usin...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218770 CAT II Cookies exchanged between the IIS 10.0 website and the clien...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218771 CAT II The IIS 10.0 website must have a unique application pool.
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218772 CAT II The maximum number of requests an application pool can proce...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218775 CAT II The application pool for each IIS 10.0 website must have a r...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218777 CAT II The application pools rapid fail protection for each IIS 10....
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218778 CAT II The application pools rapid fail protection settings for eac...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218779 CAT II Interactive scripts on the IIS 10.0 web server must be locat...
1 asset Microsoft IIS 10.0 S...
V-218780 CAT II Interactive scripts on the IIS 10.0 web server must have res...
1 asset Microsoft IIS 10.0 S...
V-218781 CAT II Backup interactive scripts on the IIS 10.0 server must be re...
1 asset Microsoft IIS 10.0 S...
V-218782 CAT II The required DoD banner page must be displayed to authentica...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-278953 CAT II HTTPAPI Server version must be removed from the HTTP Respons...
1 asset 1 Closed Microsoft IIS 10.0 S...
CUI