Information
The LBAC_DBA role allows users to administer Label-Based Access Control (LBAC) Unauthorized users can modify security labels.
Granting this role to unauthorized users can impact data access restrictions through security labels.
Solution
To remediate this setting, execute the following SQL statement, keeping in mind if this is granted in both container and pluggable database, you must connect to both places to revoke. Please ensure proper impact analysis is done before revoking the privilege from a role.
REVOKE LBAC_DBA FROM <grantee>;
In the case of a grant via a role:
REVOKE <rolename> FROM <grantee>;