DG0053: DBMS client connection definition file

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Many sites distribute a single client database connection configuration file to all site database users that contains network access information for all databases on the site. Such a file provides information to access databases not required by all users that may assist in unauthorized access attempts.

Solution

Develop, document and implement procedures to distribute client connection definitions or definition files that contain only connection definitions authorized for that user or user workstation.

Include or note these procedures in the System Security Plan.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R20_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-24628r1_rule, STIG-ID|DG0053-ORACLE11, Vuln-ID|V-3809

Plugin: Unix

Control ID: 24f5e773b9c39521b6678e934004152bb27b2289f9da8e0a6f7d133eaf2b2827