4.31 listener.ora - 'Remove extproc entry'

Information

ExtProc functionality allows external C and Java functions to be called from within PL/SQL. If extproc functionality is not required,
remove this entry. If extproc functionality is required, refer to Oracle Metalink Security Alert 57 (244523.1) for instructions on
securing extproc. In short, create a new listener specifically for extproc. This listener must run as an unprivileged OS user.

Solution

Remove extproc from the listener.ora.

See Also

https://workbench.cisecurity.org/files/574

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Windows

Control ID: c5e15685fe16d4b3ce806a0257ace6aa80e4f8acd067c3aaf3ba705ba577849c