{
"_type": "sec_certs.sample.cc.CCCertificate",
"category": "Databases",
"cert_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/c0537_eimg.pdf",
"dgst": "a43cc3e7f97cf843",
"heuristics": {
"_type": "sec_certs.sample.cc.CCCertificate.Heuristics",
"annotated_references": null,
"cert_id": "JISEC-CC-CRP-C0537",
"cert_lab": null,
"cpe_matches": {
"_type": "Set",
"elements": [
"cpe:2.3:a:microsoft:sql_server_2016:13.0.4001.0:*:*:*:*:*:*:*"
]
},
"direct_transitive_cves": null,
"eal": "EAL2+",
"extracted_sars": {
"_type": "Set",
"elements": [
{
"_type": "sec_certs.sample.sar.SAR",
"family": "ALC_FLR",
"level": 2
}
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"13.0.4001.0"
]
},
"indirect_transitive_cves": null,
"next_certificates": null,
"prev_certificates": null,
"protection_profiles": {
"_type": "Set",
"elements": [
"3f6ac99252bbf14e"
]
},
"related_cves": {
"_type": "Set",
"elements": [
"CVE-2024-37323",
"CVE-2024-35256",
"CVE-2024-37319",
"CVE-2024-37331",
"CVE-2024-37328",
"CVE-2024-37326",
"CVE-2024-37329",
"CVE-2024-37322",
"CVE-2024-35271",
"CVE-2024-37333",
"CVE-2024-37336",
"CVE-2024-38087",
"CVE-2024-21449",
"CVE-2024-37320",
"CVE-2024-37332",
"CVE-2024-35272",
"CVE-2024-37318",
"CVE-2024-37324",
"CVE-2024-37327",
"CVE-2024-37321",
"CVE-2024-38088",
"CVE-2024-37330"
]
},
"report_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"scheme_data": {
"cert_id": "JISEC-CC-CRP-C0537",
"certification_date": "2017-02-01",
"claim": "EAL2+ALC_FLR.2 PP",
"enhanced": {
"assurance_level": "EAL2 Augmented with ALC_FLR.2",
"cc_version": "3.1 Release4",
"cert_link": "https://www.ipa.go.jp/en/security/c0537_eimg.pdf",
"description": "PRODUCT DESCRIPTION Description of TOE The TOE is the database engine of SQL Server 2016. SQL Server is a Database Management System (DBMS). The TOE has been developed as the core module of the DBMS to store and manage data in a secure way. TOE security functionality This TOE provides the following security functionality: - The Access Control function of the TOE controls the access of users to user data and metadata stored in the TOE. - The Session Handling function of the TOE limits the possibilities of users to establish sessions with the TOE. - The Security Audit function of the TOE produces log files about all security relevant events. - The Security Management function allows authorized administrators to manage the behavior of the security functionality of the TOE. - The Identification and Authentication function of the TOE is able to identify and authenticate users. - The Residual Information Protection function of the TOE overwrites the residual information on the memory that will be used for user sessions.",
"evaluation_facility": "T\u00dcV Informationstechnik GmbH, Evaluation Body for IT-Security",
"product": "SQL Server 2016 Database Engine Enterprise Edition x64 (English)",
"product_type": "Database Management System (DBMS)",
"protection_profile": "Base Protection Profile for Database Management Systems (DBMS PP), Version 2.07",
"report_link": "https://www.ipa.go.jp/en/security/c0537_erpt.pdf",
"target_link": "https://www.ipa.go.jp/en/security/c0537_est.pdf",
"toe_version": "13.0.4001.0 (including Service Pack 1)",
"vendor": "Microsoft Corporation"
},
"expiration_date": "2022-03-01",
"supplier": "Microsoft Corporation",
"toe_japan_name": "-----",
"toe_overseas_link": "https://www.ipa.go.jp/en/security/jisec/software/certified-cert/c0537_it5563.html",
"toe_overseas_name": "SQL Server 2016 Database Engine Enterprise Edition x64 (English)13.0.4001.0 (including Service Pack 1)"
},
"st_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"verified_cpe_matches": null
},
"maintenance_updates": {
"_type": "Set",
"elements": []
},
"manufacturer": "Microsoft Corporation",
"manufacturer_web": "https://www.microsoft.com",
"name": "SQL Server 2016 Database Engine Enterprise Edition x64 (English) 13.0.4001.0 (including Service Pack 1)",
"not_valid_after": "2022-02-15",
"not_valid_before": "2017-02-15",
"pdf_data": {
"_type": "sec_certs.sample.cc.CCCertificate.PdfData",
"cert_filename": "c0537_eimg.pdf",
"cert_frontpage": null,
"cert_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {},
"cc_claims": {},
"cc_protection_profile_id": {},
"cc_sar": {
"ALC": {
"ALC_FLR.2": 1
}
},
"cc_security_level": {
"EAL": {
"EAL2": 1
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"TUV": {
"T\u00dcV Informationstechnik": 1
}
},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Microsoft": {
"Microsoft Corporation": 1
}
},
"vulnerability": {}
},
"cert_metadata": {
"/CreationDate": "D:20170316155916+09\u002700\u0027",
"/Creator": "Microsoft\u00ae Word 2010",
"/ModDate": "D:20170316160045+09\u002700\u0027",
"/Producer": "Microsoft\u00ae Word 2010",
"pdf_file_size_bytes": 415538,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": true,
"pdf_number_of_pages": 1
},
"report_filename": "c0537_erpt.pdf",
"report_frontpage": {},
"report_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {
"JP": {
"CRP-C0537-01": 1,
"Certification No. C0537": 1
}
},
"cc_claims": {
"A": {
"A.AUTHUSER": 1,
"A.CONNECT": 1,
"A.MANAGE": 1,
"A.NO_GENERAL_": 1,
"A.PHYSICAL": 1,
"A.SUPPORT": 1,
"A.TRAINEDUSER": 1
},
"T": {
"T.ACCESS_TSFDATA": 1,
"T.ACCESS_TSFFUNC": 1,
"T.IA_MASQUERADE": 1,
"T.IA_USER": 1,
"T.RESIDUAL_DATA": 1,
"T.TSF_COMPROMISE": 1,
"T.UNAUTHORIZED_": 1
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"ALC": {
"ALC_FLR.2": 4
}
},
"cc_security_level": {
"EAL": {
"EAL2": 4,
"EAL2 augmented": 3,
"EAL2+": 2
}
},
"cc_sfr": {},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"TUV": {
"T\u00dcV Informationstechnik": 4
}
},
"hash_function": {},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {
"CC": {
"CCMB-2012-09-001": 2,
"CCMB-2012-09-002": 2,
"CCMB-2012-09-003": 2,
"CCMB-2012-09-004": 2
}
},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Microsoft": {
"Microsoft": 5,
"Microsoft Corporation": 7
}
},
"vulnerability": {}
},
"report_metadata": {
"/CreationDate": "D:20170316160424+09\u002700\u0027",
"/Creator": "Microsoft\u00ae Word 2010",
"/ModDate": "D:20170316160534+09\u002700\u0027",
"/Producer": "Microsoft\u00ae Word 2010",
"pdf_file_size_bytes": 240723,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": true,
"pdf_number_of_pages": 33
},
"st_filename": "c0537_est.pdf",
"st_frontpage": null,
"st_keywords": {
"asymmetric_crypto": {},
"cc_cert_id": {},
"cc_claims": {
"A": {
"A.AUTHUSER": 3,
"A.CONNECT": 4,
"A.MANAGE": 3,
"A.NO_GENERAL_PURPOSE": 3,
"A.PHYSICAL": 3,
"A.SUPPORT": 4,
"A.TRAINEDUSER": 3
},
"O": {
"O.ACCESS_HISTORY": 9,
"O.ADMIN_ROLE": 8,
"O.AUDIT_GENERATI": 1,
"O.AUDIT_GENERATION": 6,
"O.DISCRETIONARY_": 1,
"O.DISCRETIONARY_ACCESS": 5,
"O.MANAGE": 11,
"O.MEDIATE": 8,
"O.RESIDUAL_INFOR": 1,
"O.RESIDUAL_INFORMATION": 8,
"O.TOE_ACCESS": 18
},
"OE": {
"OE.ADMIN": 12,
"OE.INFO_PROTECT": 19,
"OE.IT_REMOTE": 10,
"OE.IT_TRUSTED_SYSTEM": 9,
"OE.NO_GENERAL_": 2,
"OE.NO_GENERAL_PURPOSE": 6,
"OE.PHYSICAL": 8
},
"T": {
"T.ACCESS_TSFDATA": 3,
"T.ACCESS_TSFFUNC": 3,
"T.IA_MASQUERADE": 4,
"T.IA_USER": 3,
"T.RESIDUAL_DATA": 3,
"T.TSF_COMPROMISE": 4,
"T.UNAUTHORIZED_ACCESS": 4
}
},
"cc_protection_profile_id": {},
"cc_sar": {
"AGD": {
"AGD_ADD": 3
},
"ALC": {
"ALC_FLR.2": 4
}
},
"cc_security_level": {
"EAL": {
"EAL 2": 3,
"EAL 2 augmented": 1,
"EAL2": 1,
"EAL2 augmented": 1,
"EAL2+": 66
}
},
"cc_sfr": {
"FAU": {
"FAU_GEN.1": 9,
"FAU_GEN.1.1": 1,
"FAU_GEN.1.2": 1,
"FAU_GEN.2": 6,
"FAU_GEN.2.1": 1,
"FAU_SEL.1": 7,
"FAU_SEL.1.1": 1
},
"FDP": {
"FDP_ACC.1": 15,
"FDP_ACC.1.1": 1,
"FDP_ACF.1": 8,
"FDP_ACF.1.1": 2,
"FDP_ACF.1.2": 1,
"FDP_ACF.1.3": 1,
"FDP_ACF.1.4": 1,
"FDP_IFC.1": 1,
"FDP_RIP.1": 6,
"FDP_RIP.1.1": 1
},
"FIA": {
"FIA_ATD.1": 15,
"FIA_ATD.1.1": 3,
"FIA_UAU.1": 7,
"FIA_UAU.1.1": 1,
"FIA_UAU.1.2": 1,
"FIA_UID.1": 14,
"FIA_UID.1.1": 1,
"FIA_UID.1.2": 1,
"FIA_USB.1": 5
},
"FMT": {
"FMT_MOF.1": 6,
"FMT_MOF.1.1": 1,
"FMT_MSA.1": 7,
"FMT_MSA.1.1": 1,
"FMT_MSA.3": 8,
"FMT_MSA.3.1": 1,
"FMT_MSA.3.2": 1,
"FMT_MTD.1": 6,
"FMT_MTD.1.1": 1,
"FMT_REV.1": 12,
"FMT_REV.1.1": 2,
"FMT_REV.1.2": 2,
"FMT_SMF.1": 11,
"FMT_SMF.1.1": 1,
"FMT_SMR.1": 18,
"FMT_SMR.1.1": 1,
"FMT_SMR.1.2": 1
},
"FPT": {
"FPT_ITT.1": 1,
"FPT_STM.1": 1,
"FPT_TRC.1": 6,
"FPT_TRC.1.1": 1,
"FPT_TRC.1.2": 1
},
"FTA": {
"FTA_MCS.1": 7,
"FTA_MCS.1.1": 1,
"FTA_MCS.1.2": 1,
"FTA_TAH": 1,
"FTA_TSE.1": 6,
"FTA_TSE.1.1": 1
}
},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 1
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {},
"side_channel_analysis": {},
"standard_id": {},
"symmetric_crypto": {},
"technical_report_id": {},
"tee_name": {
"IBM": {
"SE": 3
}
},
"tls_cipher_suite": {},
"vendor": {
"Microsoft": {
"Microsoft": 10,
"Microsoft Corporation": 3
}
},
"vulnerability": {}
},
"st_metadata": {
"/Author": "SQL Team",
"/CreationDate": "D:20161221140607+01\u002700\u0027",
"/Creator": "Microsoft\u00ae Word 2010",
"/Keywords": "CC, ST, Common Criteria, SQL, Security Target, DBMS, Database Management System",
"/ModDate": "D:20161221140607+01\u002700\u0027",
"/Producer": "Microsoft\u00ae Word 2010",
"/Subject": "Security Target",
"/Title": "Security Target - SQL Server 2016",
"pdf_file_size_bytes": 1446524,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.microsoft.com/sqlserver/en/us/common-criteria.aspx",
"https://www.microsoft.com/licensing/servicecenter/default.aspx"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 65
}
},
"protection_profile_links": {
"_type": "Set",
"elements": [
"https://www.commoncriteriaportal.org/nfs/ccpfiles/files/ppfiles/pp0088b_pdf.pdf"
]
},
"report_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/c0537_erpt.pdf",
"scheme": "JP",
"security_level": {
"_type": "Set",
"elements": [
"ALC_FLR.2",
"EAL2+"
]
},
"st_link": "https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/c0537_est.pdf",
"state": {
"_type": "sec_certs.sample.cc.CCCertificate.InternalState",
"cert": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_garbage": false,
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"pdf_hash": "e06b4bf851a233995c42ea3442c808670fa41d0a9623dcc6edcb29d625e31239",
"txt_hash": "d6f03332aaf99dee97c2c1bee96bfbe235b26ac32e9ddd3df2b047a8bda650ba"
},
"report": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_garbage": false,
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"pdf_hash": "c01e18dbdad0c499dc46b42ce4d19384899797a509f8647ca809715d05dc16ec",
"txt_hash": "ea6efabb475d8107b300bf1572a0e13a8d393ace9dc5452dc1f81ba225faa42f"
},
"st": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_garbage": false,
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"pdf_hash": "f0c8433c7f20b1ce5fd24304cff9661223f1afad4e63512f2605f1e794bb47cb",
"txt_hash": "366a3938d32ee8c03f1719b4490a4ee05c88db9451aabecfbb21752a48f9ce6d"
}
},
"status": "archived"
}