4.8 Ensure That Database Link Passwords Are Using The Latest Encryption

Information

In Oracle databases prior to version 23ai, encrypted passwords for database links are stored in the PASSWORDX column, which can be decrypted. Oracle 23ai enhances security by storing encrypted database link passwords in the SPARE1 column, making decryption significantly more difficult.

Using the latest encryption method for database link passwords reduces the risk of credential exposure. Attackers who gain access to PASSWORDX can potentially decrypt and misuse stored credentials for unauthorized access.

Solution

After upgrading to Oracle 23ai, drop and recreate the database link to ensure that passwords are encrypted using the latest method.

Impact:

If a database link password is stored using an older encryption method, it could be decrypted and exploited, posing a security risk.

See Also

https://workbench.cisecurity.org/benchmarks/16474

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|14.8

Plugin: OracleDB

Control ID: b3d1beba8ea54e38b41f070e29981432c9e2bf78ab56ddb5cde4d63e583215ae