DG0067: DBMS account password storage

Information

Database passwords stored in clear text are vulnerable to unauthorized disclosure. Database passwords should always be encoded or encrypted when stored internally or externally to the DBMS.

Solution

Develop, document and maintain a list of DBMS database objects, database configuration files, associated scripts and applications defined within or external to the DBMS that access the database, and DBMS / user environment files/settings in the System Security Plan.

Record whether they do or do not contain DBMS passwords.

If passwords are present, ensure they are encoded or encrypted and protected by host system security.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R20_STIG.zip

Item Details

References: CAT|I, Rule-ID|SV-24641r1_rule, STIG-ID|DG0067-ORACLE11, Vuln-ID|V-3812

Plugin: Unix

Control ID: e04942091d243597eb8213ee6a04267757cc558c35b1ec4a9306d57e3808b0b3