Information
The EXTERNALROUTINE authority grants a user the privilege to create user-defined functions and procedures in a specific database.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Revoke this permission from any unauthorized users.
1. Connect to the DB2 database.
db2 => connect to $DB2DATABASE user $USERNAME using $PASSWORD
2. Run the following command from the DB2 command window-
db2 => REVOKE CREATE_EXTERNAL_ROUTINE ON DATABASE FROM USER <username>