Skip to content

Oracle application administration roles must be disabled if not required and authorized.

An XCCDF Rule

Description

<VulnDiscussion>Application administration roles, which are assigned system or elevated application object privileges, must be protected from default activation. Application administration roles are determined by system privilege assignment (create / alter / drop user) and application user role ADMIN OPTION privileges.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-219840r961863_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

For each role assignment returned, issue:

From SQL*Plus:

  alter user [username] default role all except [role];