2.1.2 Ensure 'extproc' Is Not Present in 'listener.ora'

Information

'extproc' should be removed from the 'listener.ora' to mitigate the risk that OS libraries can be invoked by the Oracle instance.

Rationale:
'extproc' allows the database to run procedures from OS libraries. These library calls can, in turn, run any OS command.

Solution

To remediate this recommendation:

Remove 'extproc' from the 'listener.ora' file.

See Also

https://workbench.cisecurity.org/files/2121

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|18.9

Plugin: Windows

Control ID: a7ad1d957818a117b5211b365cb0189845ee7727f755767d0ca6f07b3a553fde