DO0287-ORACLE11 - The Oracle SQLNET.EXPIRE_TIME parameter should be set to a value greater than 0 - '$ORACLE_HOME/network/admin/sqlnet.ora SQLNET.EXPIRE_TIME > 0'

Information

The SQLNET.EXPIRE_TIME parameter defines a limit for the frequency of active connection verification of a client connection. This prevents indefinite open connections to the database where client connections have not been terminated properly. Indefinite open connections could lead to an exhaustion of system resources or leave an open connection available for compromise.

Solution

Using a text editor or administrative tool, modify the SQLNET.ORA file on the database host server to include a limit for connection request timeouts for the listener.

Example entry (value unit is in minutes):

SQLNET.EXPIRE_TIME = 3

NOTE: Use the lowest number possible that does not generate so much network traffic that performance becomes unacceptable. The lower the number, the less likely an exhaustion of resources will occur. Set the value to the lowest number greater than 0 that is supported by the target system environment.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CAT|II, Rule-ID|SV-24893r1_rule, STIG-ID|DO0287-ORACLE11, Vuln-ID|V-3863

Plugin: Unix

Control ID: 5f60c5e304f83a7333f7c705f4d606392af434b298a34efbe4b650759b4b843e