Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15651 | DG0157-ORACLE11 | SV-24982r1_rule | EBRP-1 | Medium |
Description |
---|
Remote administration may expose configuration and sensitive data to unauthorized viewing during transit across the network or allow unauthorized administrative access to the DBMS to remote users. |
STIG | Date |
---|---|
Oracle Database 11g Installation STIG | 2014-04-02 |
Check Text ( C-19408r1_chk ) |
---|
Review the System Security Plan for authorization, assignments and usage procedures for remote DBMS administration. If remote administration of the DBMS is not documented or poorly documented, this is a Finding. If remote administration of the DBMS is not authorized and not disabled, this is a Finding. |
Fix Text (F-19561r1_fix) |
---|
Disable remote administration of the DBMS where not required. Where remote administration of the DBMS is required, develop, document and implement policy and procedures on its use. Assign remote administration privileges to IAO-authorized personnel only. Document assignments in the System Security Plan. |