extproc.exe from an Audit
We have audited and the auditors noted this finding:
External Procedure executable (extproc) is found
• \app\test\product\11.2.0\dbhome_1\bin\extproc.exe
External Procedure executable (extproc) is found
• Configuration file for:
o ExtProc=tnsnames.ora
o ExtProc SID=CLREXTPROC
Extproc is intended only to accept requests from the Oracle database server but local users can still execute commands bypassing this restriction. No authentication takes place when extproc is asked to load a library and execute a function. This allows local users to run commands as the Oracle user.
They recommend the following actions:
http://www.oracle.com/technetwork/topics/security/2003alert57-128898.pdf