7.18 Secure the WLMADM authority

Information

The WLMADM authority manages workload objects for a database. Holders of DBADM authority implicitly also hold WLMADM authority.

The WLMADM authority enables creating, altering, dropping, commenting, granting, and revoking access to workload objects for a database.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Revoke any user who should NOT have WLMADM authority:
REVOKE WLMADM ON DATABASE FROM USER <username>

See Also

https://workbench.cisecurity.org/files/1654