STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to zOS WebSphere Application Server for TSS Security Technical Implementation Guide

V-225621

CAT I (High)

Vendor-supplied user accounts for the WebSphere Application Server must be defined to the ACP.

Rule ID

SV-225621r1146193_rule

STIG

zOS WebSphere Application Server for TSS Security Technical Implementation Guide

Version

V7R2

CCIs

CCI-001762

Discussion

Vendor-supplied user accounts are defined to the ACP with factory-set passwords during the installation of the WebSphere Application Server (WAS). These user accounts are common to all WAS environments and have access to restricted resources and functions. Failure to delete vendor-supplied user accounts from the ACP may lead to unauthorized access. This exposure could compromise the integrity and availability of system services, applications, and customer data.

Check Content

Refer to the following reports produced by the ACP Data Collection:

ACF2
- ACF2CMDS.RPT(LOGONIDS).
RACF
- RACFCMDS.RPT(LISTUSER).
TSS
- TSSCMDS.RPT(@ACIDS).

Automated Analysis requires Additional Analysis.
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZWAS0040).

If the CBADMIN user account is not defined to the ACP, this is not a finding.

If the CBADMIN user account is defined to ACP and the password has NOT been changed from the vendor default of CBADMIN, this is a finding with a severity of Category I.

If the CBADMIN user account is defined to the ACP and the password has been changed from the vendor default of CBADMIN, this is a finding with a severity of Category II.

Fix Text

The ISSO will ensure that the CBADMIN user account is removed or not  defined to the ACP.