2.3.7 Ensure 'REMOTE_OS_ROLES' Is Set To 'FALSE'

Information

The remote_os_roles setting permits remote users' OS roles to be applied to database management. This setting should have a value of FALSE

Allowing remote clients OS roles to have permissions for database management could cause privilege overlaps and generally weaken security.

Solution

To remediate this setting, execute the following SQL statement and restart the instance.

ALTER SYSTEM SET REMOTE_OS_ROLES = FALSE SCOPE = SPFILE;

Note: This parameter is not modifiable at the PDB level. You must modify this parameter at the CDB level.

See Also

https://workbench.cisecurity.org/benchmarks/21740

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(1), CSCv7|16.2

Plugin: OracleDB

Control ID: c1c63daca85b4a0463dd602e88fd387ba1b417f24c559b3f8d93f85e9eae6063