SV-270523r1167746_rule
V-270523
SRG-APP-000516-DB-000363
O19C-00-009000
CAT II
10
Revoke privileges granted the WITH GRANT OPTION from non-DBA and accounts that do not own application objects or document the need for WITH GRANT OPTION and get approval.
Re-grant privileges without specifying WITH GRANT OPTION.
Note: Do not revoke the system-generated grants such as those found on SYS_PLSQL_% objects. They are system generated object types (aka ShadowTypes), created internally by Oracle when using the Pipelined Table Functions. This can result in (incorrect) compilation failures and/or invalidations when the users who are supposed to have access to the shadow types find themselves without access.
Execute the query:
select grantee||': '||owner||'.'||table_name
from dba_tab_privs
where grantable = 'YES'
and grantee not in (select distinct owner from dba_objects)
and grantee not in (select grantee from dba_role_privs where granted_role = 'DBA')
and table_name not like 'SYS_PLSQL_%'
order by grantee;
If any accounts are listed, verify accounts are documented and approved for the WITH GRANT option.
If non-DBA interactive user or application accounts have WITH GRANT without being documented and approved, this is a finding.
V-270523
False
O19C-00-009000
Execute the query:
select grantee||': '||owner||'.'||table_name
from dba_tab_privs
where grantable = 'YES'
and grantee not in (select distinct owner from dba_objects)
and grantee not in (select grantee from dba_role_privs where granted_role = 'DBA')
and table_name not like 'SYS_PLSQL_%'
order by grantee;
If any accounts are listed, verify accounts are documented and approved for the WITH GRANT option.
If non-DBA interactive user or application accounts have WITH GRANT without being documented and approved, this is a finding.
M
5672