6.8.3 Review External Tables With Preprocessor

Information

A directory object specifies an alias for a directory on the server file system where external files and data are located.

Unauthorized users with access to these directories can perform actions at the operating system level that bypass normal security controls, potentially leading to data breaches, tampering, or destruction.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Delete directories that are no longer required

DROP DIRECTORY <DIRECTORY_NAME>;

See Also

https://workbench.cisecurity.org/benchmarks/16474

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: OracleDB

Control ID: 0c182d03563d3cd019fbf3be415fff77f67e739ac1281aa9a8fcb86dbecc09a9