STIGQter STIGQter: STIG Summary: Oracle Database 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The DBMS must restrict grants to sensitive information to authorized user roles.

DISA Rule

SV-237704r667144_rule

Vulnerability Number

V-237704

Group Title

SRG-APP-000033-DB-000084

Rule Version

O121-C2-003500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define application user roles based on privilege and job function requirements.

Assign the required privileges to the role and assign the role to authorized application user accounts.

Revoke any privileges to sensitive information directly assigned to application user accounts.

Check Contents

Obtain a list of privileges assigned to user accounts. If access to sensitive information is granted to roles not authorized to access sensitive information, this is a finding.

If access to sensitive information is granted to individual accounts rather than to a role, this is a finding.

Vulnerability Number

V-237704

Documentable

False

Rule Version

O121-C2-003500

Severity Override Guidance

Obtain a list of privileges assigned to user accounts. If access to sensitive information is granted to roles not authorized to access sensitive information, this is a finding.

If access to sensitive information is granted to individual accounts rather than to a role, this is a finding.

Check Content Reference

M

Target Key

4059

Comments