Audit Requirement to change passwords for default oracle accounts and locked
Hi,
I am having auditors wanting to change passwords for default accounts created by Oracle which are already locked.
They give this documentation -
Default passwords should not be used by Oracle database users.
Rationale:
Default passwords should be considered 'well known' to attackers. Consequently, if default passwords remain in place, any attacker with access to the database can authenticate as the user with that default password.
Remote value:
DLPDBD.TCFBANK.COM: "GSMUSER""MDSYS""ORDSYS""ORDDATA""OLAPSYS""LBACSYS""SYSRAC""DVF""SYSDG""APPQOSSYS""WMSYS""REMOTE_SCHEDULER_AGENT""XDB""GSMCATUSER""OJVMSYS""SI_INFORMTN_SCHEMA""SCOTT""ORACLE_OCM""CTXSYS""ORDPLUGINS""MDDATA""GGSYS""SPATIAL_CSW_ADMIN_USR""DBSNMP""DVSYS""SYS$UMF""SYSKM""DIP""SYSBACKUP""OUTLN""GSMADMIN_INTERNAL""ANONYMOUS""DBSFWUSER"