STIGQter STIGQter: STIG Summary: Oracle Database 11.2g Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

Databases utilizing Discretionary Access Control (DAC) must enforce a policy that limits propagation of access rights.

DISA Rule

SV-238450r667524_rule

Vulnerability Number

V-238450

Group Title

SRG-APP-000328-DB-000301

Rule Version

O112-C2-006600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create and document an access propagation policy that limits the propagation of rights.

Configure the DBMS to enforce the access propagation policy.

When a user is granted access to an object they have access to the object. When a used is granted access to an object with the ADMIN option, then they can provide permissions to others. Without the ADMIN option, a user cannot grant access to an object. No configuration is required.

Check Contents

Verify the DBMS has the ability to grant permissions without the grantee receiving the right to grant those same permissions to another user.

Review organization policies regarding access propagation. If an access propagation policy limiting the propagation of rights does not exist, this is a finding.

Review DBMS configuration to verify access propagation policies are enforced by the DBMS as configured. If the DBMS does not enforce the access propagation policy, this is a finding.

Vulnerability Number

V-238450

Documentable

False

Rule Version

O112-C2-006600

Severity Override Guidance

Verify the DBMS has the ability to grant permissions without the grantee receiving the right to grant those same permissions to another user.

Review organization policies regarding access propagation. If an access propagation policy limiting the propagation of rights does not exist, this is a finding.

Review DBMS configuration to verify access propagation policies are enforced by the DBMS as configured. If the DBMS does not enforce the access propagation policy, this is a finding.

Check Content Reference

M

Target Key

4057

Comments