4.4.2 Ensure 'SELECT_CATALOG_ROLE' Is Revoked from Unauthorized 'GRANTEE'

Information

As permitting unauthorized access to the SELECT_CATALOG_ROLE can allow the disclosure of all dictionary data, this capability should be restricted according to the needs of the organization.

Solution

To remediate this setting execute the following SQL statement. REVOKE SELECT_CATALOG_ROLE FROM <grantee>;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: OracleDB

Control ID: b02b8eafdf9cd42b32f63e030e946c912f56a943f1d4120e7c074ef1a130d126