STIGQter STIGQter: STIG Summary: Oracle Database 19c Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 01 Apr 2026:

Oracle Database must only generate error messages that provide information necessary for corrective actions without revealing organization-defined sensitive or potentially harmful information in error logs and administrative messages that could be exploited.

DISA Rule

SV-270583r1065027_rule

Vulnerability Number

V-270583

Group Title

SRG-APP-000266-DB-000162

Rule Version

O19C-00-018300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DBMS and custom database and application code not to divulge sensitive information or information useful for system identification in error information.

Check Contents

Check DBMS settings and custom database and application code to verify error messages do not contain information beyond what is needed for troubleshooting the issue.

If database errors contain PII data, sensitive business data, or information useful for identifying the host system, this is a finding.

Vulnerability Number

V-270583

Documentable

False

Rule Version

O19C-00-018300

Severity Override Guidance

Check DBMS settings and custom database and application code to verify error messages do not contain information beyond what is needed for troubleshooting the issue.

If database errors contain PII data, sensitive business data, or information useful for identifying the host system, this is a finding.

Check Content Reference

M

Target Key

5672