6.5.1 Ensure 'DBA_COL_PRIVS' Is Revoked from Unauthorized 'GRANTEE'

Information

The DBA_COL_PRIVS view provides DBAs a view to manage all column level privileges granted to users and roles.

Granting DBA_COL_PRIVS privileges to unauthorized users increases the risk of data breaches, unauthorized modifications, and privilege escalation attacks. Access to this should be limited to authorized DBAs.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To remediate this recommendation, execute the following SQL statement.

REVOKE UPDATE ON <TABLE> FROM <GRANTEE>;

See Also

https://workbench.cisecurity.org/benchmarks/26139

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: OracleDB

Control ID: 362bc9895c0b675494acb4aba1a24a8329b1a199506e524ddb931ef891398d61