Database Security Products (MOSC)

MOSC Banner

extproc.exe from an Audit

edited Dec 20, 2013 3:01AM in Database Security Products (MOSC) 2 commentsAnswered ✓
Hi all,

We have audited and the auditors noted this finding:

External Procedure executable (extproc) is found
• \app\test\product\11.2.0\dbhome_1\bin\extproc.exe
External Procedure executable (extproc) is found
• Configuration file for:
o ExtProc=tnsnames.ora
o ExtProc SID=CLREXTPROC

Extproc is intended only to accept requests from the Oracle database server but local users can still execute commands bypassing this restriction. No authentication takes place when extproc is asked to load a library and execute a function. This allows local users to run commands as the Oracle user.

They recommend the following actions:

http://www.oracle.com/technetwork/topics/security/2003alert57-128898.pdf

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center