Revoke the privilege to execute the SYS.UTL_FILE package from PUBLIC?
Hi,
A vulnerability assessment of our 11i Oracle Financials system has recommended that we revoke the privilege to execute the SYS.UTL_FILE package from the PUBLIC role (as follows). This is likely to be a generic recommendation based on a scan of the Oracle Database (11gR2) and not taking into account 11i Oracle Financials using the database.
I have searched MOS (with Powerview ON) but cannot find any recommendations; Securing the E-Business Suite [189367.1] does not advise revoking the privilege. Is there any advice from the Community if it is appropriate to revoke the privilege from PUBLIC for 11i Oracle Financials?
Tagged:
0