STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

The SQLNet SQLNET.ALLOWED_LOGON_VERSION parameter must be set to a value of 11 or higher.

DISA Rule

SV-24958r2_rule

Vulnerability Number

V-16057

Group Title

SQLNET.ALLOWED_LOGON_VERSION

Rule Version

DO6751-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the SQLNET.ORA file to add or edit the entry:

SQLNET.ALLOWED_LOGON_VERSION = 11

Set the value to 11 or higher.

Check Contents

View the SQLNET.ORA file in the ORACLE_HOME/network/admin directory or the directory specified in the TNS_ADMIN environment variable.

Locate the following entry:

SQLNET.ALLOWED_LOGON_VERSION = 11

If the parameter does not exist, this is a Finding.

If the parameter is not set to a value of 11 or higher, this is a Finding.

Vulnerability Number

V-16057

Documentable

False

Rule Version

DO6751-ORACLE11

Severity Override Guidance

View the SQLNET.ORA file in the ORACLE_HOME/network/admin directory or the directory specified in the TNS_ADMIN environment variable.

Locate the following entry:

SQLNET.ALLOWED_LOGON_VERSION = 11

If the parameter does not exist, this is a Finding.

If the parameter is not set to a value of 11 or higher, this is a Finding.

Check Content Reference

M

Responsibility

Database Administrator

Target Key

1368

Comments