I just received an audit report by an external service provider. Some points in this report seems st
An excerpt of this report:
|
|
|
|
| Windows Program Folder Permissions | Verify and set permissions | Rationale: The Oracle program installation folder must allow only limited access. Global access or unrestricted folder permissions will allow an attacker to alter Oracle resources and possibly compromise the security of the Oracle system. Remediation: Remove permissions for the Users group from the %ProgramFiles%\Oracle folder. Audit: Execute the following command: cacls “%ProgramFiles%\Oracle” and ensure BUILTIN\Users is not listed. |
10 | Windows Oracle Registry Key Permissions | Verify and set permissions | Rationale: Access to the Oracle registry key must be limited to those users that require it. Unrestricted access to the |