4.1.4 Disable Database Discovery (DISCOVER_DB)

Information

The DISCOVER_DB parameter specifies whether the database can be discovered in the network. It is recommended that databases not be discoverable.

Discovery capabilities may be used by a malicious entity to derive the names of and target Db2 databases.

Solution

- Connect to the Db2 database db2 => connect to <dbname>
- Run the following command: db2 => update database configuration using discover_db disable

See Also

https://workbench.cisecurity.org/benchmarks/15333

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 24c886d7852190b955a0fcd90195a9505c870d4e183b0bfaf268717ea3a6a528