DO6747: Connection Manager remote administration - '%ORACLE_HOME%\NETWORK\ADMIN\CMAN.ORA REMOTE_ADMIN = no'

Information

The use of IP address in place of host names helps to protect against malicious corruption or spoofing of host names. Use of static IP addresses is considered more stable and reliable than use of hostnames or Fully Qualified Domain Names (FQDN).

Solution

Edit the listener.ora file and replace any HOST= [hostname or domain name] to use static IP addresses for the host.

The listener.ora file is by default located in the ORACLE_HOME/network/admin directory or the directory specified in the TNS_ADMIN environment variable for the listener service or process owner account.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R19_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|III, Rule-ID|SV-24955r1_rule, STIG-ID|DO6747-ORACLE11, Vuln-ID|V-16032

Plugin: Windows

Control ID: 87aecee752a0530f7bda218539e7daa4750779fa9c213a0cb7be098071d0f3c1