Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15105 | DG0120-ORACLE10 | SV-24749r1_rule | ECLP-1 | Medium |
Description |
---|
Access to objects stored and/or executed outside of the DBMS security context may provide an avenue of attack to host system resources not controlled by the DBMS. Any access to external resources from the DBMS can lead to a compromise of the host system or its resources. |
STIG | Date |
---|---|
Oracle Database 10g Installation STIG | 2014-04-02 |
Check Text ( C-1013r1_chk ) |
---|
Review definitions and access restrictions to objects stored outside of DBMS control. View object application data types defined in the database, but stored outside of the DBMS. View data objects that include host file and directory references in their definitions. If any external objects exist that are not referenced and authorized in the System Security Plan, this is a Finding. |
Fix Text (F-24519r1_fix) |
---|
Evaluate the associated risk in allowing access to external objects. Consider the security context under which the object is accessed or whether the privileges required to access the object are available for assignment based on job function. Where feasible, modify the application to use only objects stored internally to the database. Where not feasible, note the risk assessment and acceptance in the System Security Plan for access to external objects. |