Database Utilities (MOSC)

MOSC Banner

Security concerns regarding db links, export/import(datapump), and password exposure

Our security team has concerns regarding password exposure in dump files created by logical exports.

I am looking for the versions and applicable patch numbers that exposed the password or the password hash in the export files for database links.

Also is it possible to prevent the export of the database link password metadata on a system level? Essentially require that creating a dblink must include providing the password rather than allowing for it to be created based on :1 internal values from an extract.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center