Korean
<< Back
VID 25160
Severity 40
Port 1521, ...
Protocol TCP
Class DB
Detailed Description The ORACLE server on the host system sets OS_ROLES to TRUE.
If OS_ROLES is set to TRUE, The operating system completely manages the role grants for all database usernames.

* Platforms Affected:
UNIX any version
Linux any version
Microsoft Windows any version
Recommendation Open $Oracle_Home/dbs/SPFILE<SID>.ORA or $Oracle_Home/admin/pfile/init<sid>.ora and add the following.
OS_ROLES=FALSE
Related URL CVE-2001-499 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)