4.5.2 Ensure 'ALL' Is Revoked from Unauthorized 'GRANTEE' on 'USER_HISTORY$'

Information

As permitting non-privileged users the authorization to manipulate the records in the SYS.USER_HISTORY$ table can allow distortion of the audit trail, potentially hiding unauthorized data confidentiality attacks or integrity changes, this capability should be restricted according to the needs of the organization.

Solution

To remediate this setting execute the following SQL statement. REVOKE ALL ON USER_HISTORY$ FROM <grantee>;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: OracleDB

Control ID: 5f882181a4fc87de6f6a88f34ff84556c547291c9a89a36863b62c545226f1bc