7.11 Secure the implicit schema role

Information

The IMPLSCHEMA (implicit schema) role grants the authority to a user to create objects without specifying a schema that already exists. It is recommended that the IMPLSCHEMA role be granted to authorized users only.

Review all users that have access to this authority.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Revoke this permission from any unauthorized users.
1. Connect to the DB2 database.
db2 => connect to $DB2INSTANCE user $USERNAME using $PASSWORD
2. Run the following command from the DB2 command window:
db2 => REVOKE IMPLICIT_SCHEMA ON DATABASE FROM USER <username>

See Also

https://workbench.cisecurity.org/files/1654