STIGQter STIGQter: STIG Summary: Oracle Database 11.2g Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The DBMS must restrict grants to sensitive information to authorized user roles.

DISA Rule

SV-238439r667491_rule

Vulnerability Number

V-238439

Group Title

SRG-APP-000033-DB-000084

Rule Version

O112-C2-003500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define application user roles based on privilege and job function requirements.

Assign the required privileges to the role and assign the role to authorized application user accounts.

Revoke any privileges to sensitive information directly assigned to application user accounts.

Check Contents

Obtain a list of privileges assigned to user accounts. If access to sensitive information is granted to roles not authorized to access sensitive information, this is a finding.

If access to sensitive information is granted to individual accounts rather than to a role, this is a finding.

Vulnerability Number

V-238439

Documentable

False

Rule Version

O112-C2-003500

Severity Override Guidance

Obtain a list of privileges assigned to user accounts. If access to sensitive information is granted to roles not authorized to access sensitive information, this is a finding.

If access to sensitive information is granted to individual accounts rather than to a role, this is a finding.

Check Content Reference

M

Target Key

4057

Comments