OL09-00-000232 - OL 9 must restrict privilege elevation to authorized personnel.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If the sudoers file is not configured correctly, any user defined on the system can initiate privileged actions on the target system.

Solution

Remove the following entries from the /etc/sudoers file or configuration file under /etc/sudoers.d/:

ALL ALL=(ALL) ALL
ALL ALL=(ALL:ALL) ALL

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R2_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-271476r1091140_rule, STIG-ID|OL09-00-000232, Vuln-ID|V-271476

Plugin: Unix

Control ID: 2a807ae4b140e465b95cea421840ef9cecf97abb7d2e46938a5f1e04659365bc