7.10 Secure the NOFENCE role

Information

The NOFENCE role grants the authority to a user to create user-defined functions or procedures that are not fenced in the memory block of the database. It is recommended that the NOFENCE role be granted to authorized users only.

Review all users that have access to this authority.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Revoke this permission from any unauthorized users.
1. Connect to the DB2 database.
db2 => connect to $DB2INSTANCE user $USERNAME using $PASSWORD
2. Run the following command from the DB2 command window:
db2 => REVOKE CREATE_NOT_FENCED_ROUTINE ON DATABASE FROM USER <username>

See Also

https://workbench.cisecurity.org/files/1654