2.1.2 Ensure 'extproc' Is Not Present in 'listener.ora'

Information

'extproc' should be removed from the 'listener.ora' to mitigate the risk that OS libraries can be invoked by the Oracle instance.

Rationale:
'extproc' allows the database to run procedures from OS libraries. These library calls can, in turn, run any OS command.

Solution

To remediate this recommendation:

Remove 'extproc' from the 'listener.ora' file.

See Also

https://workbench.cisecurity.org/files/2121

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|18.9

Plugin: Unix

Control ID: bdac9849fb40a8a3ac1e5fda262579c4c992c8b731f1471cea61031dfc23581f