4.5.5 Ensure 'ALL' Is Revoked from Unauthorized 'GRANTEE' on 'DBA_%'

Information

As permitting users the authorization to manipulate the DBA_ views can expose sensitive data.

Solution

Replace <non-DBA/SYS grantee>, in the query below, with the Oracle login(s) or role(s) returned from the associated audit procedure and execute: REVOKE ALL ON DBA_ FROM <Non-DBA/SYS grantee>;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: OracleDB

Control ID: 0b09c62e82220fb546a3abdce3a7f8ffd72559a6639cfb7d78267cc4010b2124