O19C-00-008600 - Oracle instance names must not contain Oracle version numbers.

Information

Service names may be discovered by unauthenticated users. If the service name includes version numbers or other database product information, a malicious user may use that information to develop a targeted attack.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Follow the instructions in Oracle MetaLink Note 15390.1 (and related documents) to change the SID for the database without recreating the database to a value that does not identify the Oracle version.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_19c_V1R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-270521r1064841_rule, STIG-ID|O19C-00-008600, Vuln-ID|V-270521

Plugin: OracleDB

Control ID: a73acd02244ca5b472cb6a4cc17747e404917b68a7d707662806c8c5f3a4ba24