6.8.1 Ensure Directory Object Access Is Revoked From Unauthorized 'GRANTEE'

Information

A directory object specifies an alias for a directory on the server file system where external files and data are located.

Users with access to these directories can perform actions at the operating system level that bypass normal security controls, potentially leading to data breaches, tampering, or destruction.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To remediate this recommendation, execute the following SQL statement to delete directories which are no longer required.

DROP DIRECTORY <DIRECTORY_NAME>;

See Also

https://workbench.cisecurity.org/benchmarks/21740

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: OracleDB

Control ID: 393b2921c4ae1b55870a1c5e1dee93a390fb276b803e487a494656cc434fa1eb