DO0420-ORACLE11 - The XDB Protocol server should be uninstalled if not required and authorized for use - 'No XDB users exist'

Information

The XML DB supports storage and retrieval of XML data objects in the Oracle Database. It requires the configuration of an Oracle shared-server dispatcher that is activated / used by the Oracle listener to pass http XML requests. If this service is not required, it should be uninstalled.

Solution

If the database is authorized to support web services using XML over HTTP, then include documentation and authorization in the System Security Plan.

If not authorized, uninstall XML DB per Oracle MetaLink Note 742014.1.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CAT|III, Rule-ID|SV-24899r1_rule, STIG-ID|DO0420-ORACLE11, Vuln-ID|V-3865

Plugin: OracleDB

Control ID: 93a850abc3b23cdda9b216f36e1628ebf03065e037fbd448ab27fd2a1e59e219