VID |
25160 |
Severity |
40 |
Port |
1521, ... |
Protocol |
TCP |
Class |
DB |
Detailed Description |
The ORACLE server on the host system sets OS_ROLES to TRUE. If OS_ROLES is set to TRUE, The operating system completely manages the role grants for all database usernames.
* Platforms Affected: UNIX any version Linux any version Microsoft Windows any version |
Recommendation |
Open $Oracle_Home/dbs/SPFILE<SID>.ORA or $Oracle_Home/admin/pfile/init<sid>.ora and add the following. OS_ROLES=FALSE |
Related URL |
CVE-2001-499 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|