4.5.5 Ensure 'ALL' Is Revoked from Unauthorized 'GRANTEE' on 'DBA_%'
Information
As permitting users the authorization to manipulate the DBA_ views can expose sensitive data.
Solution
Replace <non-DBA/SYS grantee>, in the query below, with the Oracle login(s) or role(s) returned from the associated audit procedure and execute: REVOKE ALL ON DBA_ FROM <Non-DBA/SYS grantee>;