Oracle application administration roles must be disabled if not required and authorized.
An XCCDF Rule
Description
<VulnDiscussion>Application administration roles, which are assigned system or elevated application object privileges, should be protected from default activation. Application administration roles are determined by system privilege assignment (create / alter / drop user) and application user role ADMIN OPTION privileges.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-219712r879887_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
For each role assignment returned, issue:
From SQL*Plus:
alter user [username] default role all except [role];