2.1.2 Ensure 'extproc' Is Not Present in 'listener.ora'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

extproc should be removed from the listener.ora to mitigate the risk that OS libraries can be invoked by the Oracle instance.

Rationale:

extproc allows the database to run procedures from OS libraries. These library calls can, in turn, run any OS command.

Solution

To remediate this recommendation:
Remove extproc from the listener.ora file.

See Also

https://workbench.cisecurity.org/files/2868