DG0190-ORACLE11 - Credentials stored and used by the DBMS to access remote databases or applications should be authorized and restricted to authorized users.

Information

Credentials defined for access to remote databases or applications may provide unauthorized access to additional databases and applications to unauthorized or malicious users.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Grant access to database links to authorized users or applications only.

Document all database links access authorizations in the System Security Plan.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-25082r1_rule, STIG-ID|DG0190-ORACLE11, Vuln-ID|V-15154

Plugin: OracleDB

Control ID: 798e84f3e84aaa34045a8701d0de627f234eadab4c37b6491160d4b94357daa2