4.28 listener.ora - 'Use absolute paths in ENVS parameters'

Information

Allowing overly broad PATH and CLASSPATH variables could allow an attacker to leverage pathing issues and load malicious binaries or
classes.
NOTE: Ensure only full paths are being utilized when the ENVS parameter is used.
Level 2, Not Scorable

See Also

https://workbench.cisecurity.org/files/580

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(2), CSCv6|8.4

Plugin: Windows

Control ID: 5d7de9c9fda949fbe1d47ce1143889d25b6c64c205d58759db131c01b58a412b