DG0171-ORACLE11 - The DBMS should not have a connection defined to access or be accessed by a DBMS at a different classification level.

Information

Applications that access databases and databases connecting to remote databases that differ in their assigned classification levels may expose sensitive data to unauthorized clients. Any interconnections between databases or applications and databases differing in classification levels are required to comply with interface control rules.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Disassociate or remove connection definitions to remote systems of differing classification levels.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Database_11g_Y21M10_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-25075r1_rule, STIG-ID|DG0171-ORACLE11, Vuln-ID|V-15656

Plugin: Unix

Control ID: fd99a29b7551593bc571f069519cedb67da0a50735855acbfeac5bb15b088094