Security concerns regarding db links, export/import(datapump), and password exposure
Our security team has concerns regarding password exposure in dump files created by logical exports.
I am looking for the versions and applicable patch numbers that exposed the password or the password hash in the export files for database links.
Also is it possible to prevent the export of the database link password metadata on a system level? Essentially require that creating a dblink must include providing the password rather than allowing for it to be created based on :1 internal values from an extract.