STIGQter STIGQter: STIG Summary: Oracle Database 11g Instance STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

DBMS application user roles should not be assigned unauthorized privileges.

DISA Rule

SV-24705r1_rule

Vulnerability Number

V-15128

Group Title

DBMS application user role privilege assignment

Rule Version

DG0105-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use the grant and revoke commands to assign the authorized privileges as listed in the System Security Plan to custom database application or application user roles.

Check Contents

Compare privileges assigned to database application user roles to those defined in the System Security Plan.

If the assigned privileges do not match the authorized list of privileges, this is a Finding.

Vulnerability Number

V-15128

Documentable

False

Rule Version

DG0105-ORACLE11

Severity Override Guidance

Compare privileges assigned to database application user roles to those defined in the System Security Plan.

If the assigned privileges do not match the authorized list of privileges, this is a Finding.

Check Content Reference

M

Responsibility

Database Administrator

Target Key

1367

Comments