OL 8 must not have the "iprutils" package installed if not required for operational support.

STIG ID: OL08-00-040380  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium |  CCI: CCI-000366 |  Vulnerability Id: V-248905 | 

Vulnerability Discussion

The "iprutils" package provides a suite of utilities to manage and configure IBM Power Linux RAID Adapters supported by the IPR SCSI storage device driver. Disabling the "iprutils" package protects the system against exploitation of any flaws in its implementation.

Check

Determine if the "iprutils" package is installed with the following command:

$ sudo yum list installed iprutils

If the "iprutils" package is installed, this is a finding.

Fix

Configure OL 8 to disable non-essential capabilities by removing the "iprutils" package from the system with the following command:

$ sudo yum remove iprutils