SQL6-D0-002900 - Execution of stored procedures and functions that utilize execute as must be restricted to necessary cases only.


In certain situations, to provide required functionality, a DBMS needs to execute internal logic (stored procedures, functions, triggers, etc.) and/or external code modules with elevated privileges. However, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking the functionality applications/programs, those users are indirectly provided with greater privileges than assigned by organizations.

Privilege elevation must be utilized only where necessary and protected from misuse.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.


Alter stored procedures and functions to remove the 'EXECUTE AS' statement.

