DG0130-ORACLE11 - DBMS passwords should not be stored in compiled, encoded or encrypted batch jobs or compiled, encoded or encrypted application source code.

Information

The storage of passwords in application source or batch job code that is compiled, encoded or encrypted prevents compliance with password expiration and other management requirements as well as provides another means for potential discovery.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Design DBMS application code and batch job code that is compiled, encoded or encrypted to NOT contain passwords.

Consider alternatives to using password authentication for compiled, encoded or encrypted batch jobs and DBMS application code.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|II, Rule-ID|SV-24968r2_rule, STIG-ID|DG0130-ORACLE11, Vuln-ID|V-15637

Plugin: OracleDB

Control ID: 1bdbb0810bbd6bc78fb828463da346426422c4dd1ffc8f8320c016ed00d981fa