From Application Security and Development Security Technical Implementation Guide
Part of SRG-APP-000211
Associated with: CCI-001082
Application management functionality includes functions necessary for administration and requires privileged user access. Allowing non-privileged users to access application management functionality capabilities increases the risk that non-privileged users may obtain elevated privileges.
Review the application documentation and interview the application administrator. Review the design documents and the interfaces used by the application. Verify that the application provides separate interfaces for user traffic and for management traffic. The separation may be virtual in nature (virtual host, virtual NIC, virtual network) or physically separate. If the application user interface and the application management interface are shared, this is a finding.
Configure the application so user interface to the application and management interface to the application is separated.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer