4.8 Ensure That Database Link Passwords Are Using The Latest Encryption

Information

In Oracle databases, encrypted passwords for database links are stored in the PASSWORDX column, which can be decrypted.

Attackers who gain access to PASSWORDX can potentially decrypt and misuse stored credentials for unauthorized access.

Solution

Drop and recreate the database link to ensure that passwords are encrypted using the latest method.

Impact:

If a database link password is stored using an older encryption method, it could be decrypted and exploited, posing a security risk.

See Also

https://workbench.cisecurity.org/benchmarks/23897

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|14.8

Plugin: OracleDB

Control ID: 5b58ed682000508e0a8c0941c6bbf997a6a6b56062699a26170e0cc91fd80a71