3.1.6 Disable Client Discovery Requests (DISCOVER)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The DISCOVER parameter determines what kind of discovery requests, if any, the Db2 client can make. It is recommended that this is disabled.

Rationale:

Discovery capabilities may be used by a malicious entity to derive the names of and target Db2 instances. In this configuration, the client can not issue discovery requests.

Solution

Run the following command:

db2 => update database manager configuration using discover disable

See Also

https://workbench.cisecurity.org/files/4033