SV-238449r667521_rule
V-238449
SRG-APP-000516-DB-000363
O112-C2-005000
CAT II
10
(This addresses both O112-C2-005000 and O112-C2-005200.)
Configure the DBMS settings to specify the maximum number of consecutive failed login attempts to 3 (or less):
ALTER PROFILE '&PROFILE_NAME' LIMIT FAILED_LOGON_ATTEMPTS 3;
(This addresses both O112-C2-005000 and O112-C2-005200.)
The limit on the number of consecutive failed logon attempts is defined in the profile assigned to a user.
To see what profile is assigned to a user, enter the following query:
SQL>SELECT profile FROM dba_users WHERE username = '&USERNAME'
This will return the profile name assigned to that user.
Now check the values assigned to the profile returned from the query above:
SQL>SELECT PROFILE, RESOURCE_NAME, LIMIT FROM DBA_PROFILES WHERE PROFILE LIKE '&PROFILE_NAME'
Check the settings for failed_login_attempts - this is the number of consecutive failed login attempts before locking the Oracle user account. If the value is greater than 3, this is a finding.
V-238449
False
O112-C2-005000
(This addresses both O112-C2-005000 and O112-C2-005200.)
The limit on the number of consecutive failed logon attempts is defined in the profile assigned to a user.
To see what profile is assigned to a user, enter the following query:
SQL>SELECT profile FROM dba_users WHERE username = '&USERNAME'
This will return the profile name assigned to that user.
Now check the values assigned to the profile returned from the query above:
SQL>SELECT PROFILE, RESOURCE_NAME, LIMIT FROM DBA_PROFILES WHERE PROFILE LIKE '&PROFILE_NAME'
Check the settings for failed_login_attempts - this is the number of consecutive failed login attempts before locking the Oracle user account. If the value is greater than 3, this is a finding.
M
4057