Database Security Products (MOSC)

MOSC Banner

Clarification on STIG V-270523: Revoke WITH GRANT OPTION

edited May 13, 2025 1:54AM in Database Security Products (MOSC) 6 commentsAnswered ✓

Hello All,

I'm seeking clarification on STIG Group ID V-270523 for Oracle 19c (Release 1, dated 28 Jan 2025), which states:

"Revoke WITH GRANT OPTION to accounts that do not own application objects."
(STIG Reference – V-270523)
(Check Oracle 19c Database Security Technical Implementation Guide, Jan 2025 release)

In our environment, some web application accounts require the WITH GRANT OPTION privilege—for example, to support views that enforce row-level access or to manage custom role delegation. While I understand the underlying concern is about breaking privilege traceability and losing centralized control over object access, this pattern seems relatively common in application-layer security design.

My questions:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center