STIGQter STIGQter: STIG Summary: Oracle Database 12c Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

Databases utilizing Discretionary Access Control (DAC) must enforce a policy that limits propagation of access rights.

DISA Rule

SV-237715r667177_rule

Vulnerability Number

V-237715

Group Title

SRG-APP-000328-DB-000301

Rule Version

O121-C2-006600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create and document an access propagation policy that limits the propagation of rights.

Configure the DBMS to enforce the access propagation policy.

When a user is granted access to an object, they have access to the object. When a user is granted access to an object with the GRANT option, then they can provide permissions to others. Without the GRANT option, a user cannot grant access to an object. No configuration is required.

Check Contents

Verify the DBMS has the ability to grant permissions without the grantee receiving the right to grant those same permissions to another user.

Review organization policies regarding access propagation. If an access propagation policy limiting the propagation of rights does not exist, this is a finding.

Review DBMS configuration to verify access propagation policies are enforced by the DBMS as configured. If the DBMS does not enforce the access propagation policy, this is a finding.

Vulnerability Number

V-237715

Documentable

False

Rule Version

O121-C2-006600

Severity Override Guidance

Verify the DBMS has the ability to grant permissions without the grantee receiving the right to grant those same permissions to another user.

Review organization policies regarding access propagation. If an access propagation policy limiting the propagation of rights does not exist, this is a finding.

Review DBMS configuration to verify access propagation policies are enforced by the DBMS as configured. If the DBMS does not enforce the access propagation policy, this is a finding.

Check Content Reference

M

Target Key

4059

Comments