The CA API Gateway must reveal error messages only to the ISSO, ISSM, and SCA.

From CA API Gateway ALG Security Technical Implementation Guide

Part of SRG-NET-000402-ALG-000130

Associated with: CCI-001314

SV-86091r1_rule The CA API Gateway must reveal error messages only to the ISSO, ISSM, and SCA.

Vulnerability discussion

Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can give configuration details about the network element.Limiting access to system logs and administrative consoles to authorized personnel will help to mitigate this risk. However, user feedback and error messages should also be restricted by type and content in accordance with security best practices (e.g., ICMP messages).The CA API Gateway must be configured within the policies of a Registered Service to only pass limited error messaging to the end user of a Registered Service. Additional error messages will be recorded in audit logs, and the audit logs are controlled via role-based access.

Check content

Open the CA API Gateway - Policy Manager and double-click all Registered Services requiring limited error messaging feedback to end users. Verify that the policy is configured to deliver limited error feedback to the user via the "Customize Error Response" and/or "Customize Soap Fault Response" Assertion in accordance with organizational requirements. If it is not, this is a finding.

Fix text

Open the CA API Gateway - Policy Manager and double-click all Registered Services requiring limited error messaging feedback to end users that were not configured properly. Add the "Customize Error Response" and/or "Customize Soap Fault Response" Assertion and configure in accordance with organizational requirements.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer