DO6753-ORACLE11 - Oracle Application Express or Oracle HTML DB should not be installed on a production database.

Information

The Oracle Application Express, formerly called HTML DB, is an application development component installed by default with Oracle. Unauthorized application development can introduce a variety of vulnerabilities to the database.

Solution

Remove Application Express using the instruction found in Oracle MetaLink Note 558340.1 from production DBMS systems.

For new installations, select custom installation and de-select Application Express from the selectable options if available.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, Rule-ID|SV-24961r1_rule, STIG-ID|DO6753-ORACLE11, Vuln-ID|V-16055

Plugin: OracleDB

Control ID: caf55dc158c87332208120dd5f6a28522f2e698690897d08bd4860b8b3212152