STIGQter STIGQter: STIG Summary: Oracle Database 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

Administrators must utilize a separate, distinct administrative account when performing administrative activities, accessing database security functions, or accessing security-relevant information.

DISA Rule

SV-237710r667162_rule

Vulnerability Number

V-237710

Group Title

SRG-APP-000233-DB-000124

Rule Version

O121-C2-004100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Revoke DBA privileges, and privileges to administer DBA-owned objects, from non-DBA accounts.

Provide separate accounts to DBA for database administration.

Check Contents

Review permissions for objects owned by DBA or other administrative accounts.

If any objects owned by administrative accounts can be accessed by non-DBA/non-administrative users, either directly or indirectly, this is a finding.

Verify DBAs have separate administrative accounts.

If DBAs do not have a separate account for database administration purposes, this is a finding.

To list all objects owned by an administrative account that have had access granted to another account, run the query:

SELECT grantee, table_name, grantor, privilege, type from dba_tab_privs where owner= '<applicable account>';

Vulnerability Number

V-237710

Documentable

False

Rule Version

O121-C2-004100

Severity Override Guidance

Review permissions for objects owned by DBA or other administrative accounts.

If any objects owned by administrative accounts can be accessed by non-DBA/non-administrative users, either directly or indirectly, this is a finding.

Verify DBAs have separate administrative accounts.

If DBAs do not have a separate account for database administration purposes, this is a finding.

To list all objects owned by an administrative account that have had access granted to another account, run the query:

SELECT grantee, table_name, grantor, privilege, type from dba_tab_privs where owner= '<applicable account>';

Check Content Reference

M

Target Key

4059

Comments