O19C-00-009200 - The Oracle REMOTE_OS_ROLES parameter must be set to FALSE.

Information

Setting REMOTE_OS_ROLES to TRUE allows operating system groups to control Oracle roles. The default value of FALSE causes roles to be identified and managed by the database. If REMOTE_OS_ROLES is set to TRUE, a remote user could impersonate another operating system user over a network connection.

DOD requires the REMOTE_OS_ROLES to be set to FALSE.

Solution

Set the parameter to FALSE for all instances. If using Oracle Multitenant, set the value to FALSE for the container database and all pluggable databases will be set to FALSE as well.

ALTER SYSTEM SET remote_os_roles = FALSE scope=spfile;

sid='container_name' is optional

Restart the database for the change to take effect.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_19c_V1R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-270524r1064850_rule, STIG-ID|O19C-00-009200, Vuln-ID|V-270524

Plugin: OracleDB

Control ID: 98496408fb2155c176a720dd535c3778427010471324fa840d51559e6953dedc