STIGUI
V-225629CAT II Medium severitySV-225629r1146215_rule

WebSphere MQ security class(es) must not be defined improperly.

Rule version ZWMQ0049 · STIG v7 · 2026-06-03

Discussion

WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security checking. Failure to properly protect WebSphere MQ resources may result in unauthorized access. This exposure could compromise the availability, integrity, and confidentiality of system services, applications, and customer data.

Check

Refer to the following reports produced by the TSS Data Collection:

- TSSCMDS.RPT(#RDT). - SENSITVE.RPT(WHOOMADM). - SENSITVE.RPT(WHOOMCMD). - SENSITVE.RPT(WHOOMCON). - SENSITVE.RPT(WHOOMNLI). - SENSITVE.RPT(WHOOMPRO.) - SENSITVE.RPT(WHOOMQUE). - SENSITVE.RPT(WHOOXADM). - SENSITVE.RPT(WHOOXNLI). - SENSITVE.RPT(WHOOXPRO). - SENSITVE.RPT(WHOOXQUE). - SENSITVE.RPT(WHOOXTOP).

If the following WebSphere MQ Resource Class(es) is (are) defined in the Resource Definition Table (RDT), this is not a finding.

MQADMIN MQCMDS MQCONN MQNLIST MQPROC MQQUEUE

When SCYCASE is set to MIXED, and the following WebSphere MQ Resource Class(es) is (are) defined in the Resource Definition Table (RDT), this is not a finding.

MXADMIN MXNLIST MXPROC MXQUEUE MXTOPIC

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

Note: If both MQADMIN and MXADMIN resource classes are not defined to the RDT record, no security checking is performed.

Fix

Ensure that all WebSphere MQ resources are defined to TSS.

The following should be defined to the RDT:

MQADMIN MQCONN MQCMDS MQNLIST MQPROC MQQUEUE

When SCYCASE is set to mixed, and the following WebSphere MQ resource classes should be defined to the TSS RDT.

MXADMIN MXNLIST MXPROC MXQUEUE MXTOPIC

Use the following commands to define (establish ownership of) resources for each WebSphere MQ subsystem to TSS:

TSS ADD(deptname) MQADMIN(ssid.) TSS ADD(deptname) MQCMDS(ssid.) TSS ADD(deptname) MQCONN(ssid.) TSS ADD(deptname) MQNLIST(ssid.) TSS ADD(deptname) MQPROC(ssid.) TSS ADD(deptname) MQQUEUE(ssid.)

When SCYCASE is set to mixed, CLASMAP Definitions must include the following entries:

TSS ADD(deptname) MXADMIN(ssid.) TSS ADD(deptname) MXNLIST(ssid.) TSS ADD(deptname) MXPROC(ssid.) TSS ADD(deptname) MXQUEUE(ssid.) TSS ADD(deptname) MXTOPIC(ssid.)

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

Another method to ensure protection is to assign the DEFPROT attribute to the resource class in the RDT record by using the following command:

TSS REP(RDT) RESCLASS(MQADMIN) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MQCMDS) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MQCONN) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MQNLIST) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MQPROC) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MQQUEUE) ATTR(DEFPROT)

When SCYCASE is set to mixed.

TSS REP(RDT) RESCLASS(MXADMIN) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MXNLIST) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MXPROC) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MXQUEUE) ATTR(DEFPROT) TSS REP(RDT) RESCLASS(MXTOPIC) ATTR(DEFPROT)

Identifiers

Group ID
V-225629
Group title
SRG-OS-000080
Rule ID
SV-225629r1146215_rule
Check ID
C-27330r1146213_chk
Fix ID
F-27318r1146214_fix