Unauthorized database links must not be defined and active.
An XCCDF Rule
Description
<VulnDiscussion>DBMS links provide a communication and data transfer path definition between two databases that may be used by malicious users to discover and obtain unauthorized access to remote systems. Database links between production and development DBMSs provide a means for developers to access production data not authorized for their access or to introduce untested or unauthorized applications to the production database. Only protected, controlled, and authorized downloads of any production data to use for development should be allowed. Only applications that have completed the configuration management process should be introduced by the application object owner account to the production system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-219715r879887_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Document all remote or external interfaces used by the DBMS to connect to or allow connections from remote or external sources.
Include with the documentation as appropriate, any network ports or protocols, security accounts, and the sensitivity of any data exchanged.
Do not define or configure database links between production databases and test or development databases.