SV-271302r1109113_rule
V-271302
SRG-APP-000141-DB-000093
SQLI-22-007200
CAT II
10
Disable use of or remove any external application executable object definitions that are not approved.
To disable the use of xp_cmdshell, from the query prompt:
EXEC SP_CONFIGURE 'show advanced options', 1;
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'xp_cmdshell', 0;
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'show advanced options', 0;
RECONFIGURE WITH OVERRIDE;
To determine if [xp_cmdshell] is enabled, execute the following command:
SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'xp_cmdshell'
If [value_in_use] is a [1], review the system documentation to determine whether the use of [xp_cmdshell] is approved. If it is not approved, this is a finding.
V-271302
False
SQLI-22-007200
To determine if [xp_cmdshell] is enabled, execute the following command:
SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'xp_cmdshell'
If [value_in_use] is a [1], review the system documentation to determine whether the use of [xp_cmdshell] is approved. If it is not approved, this is a finding.
M
5677