Skip to Main Content

Database Software

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Security on ALL_USERS

marceloTNov 10 2017 — edited Nov 13 2017

Hi,

   Doing some security assessments I realized that a user with just create session can query the ALL_USERS view and get a listing of all the users defined in the database.

  Some people ask if that i really a risk for a user A to know that user B exists even if A has no access to any data of user B. I think that YES, user A might try to connect as user B and depending on the security configuration of the database, user A might succeed or user B could get blocked after several attemps from user A, and if user B gets locked that might lead to denial of service

is it safe to do a revoke select on all_users from public? Any other suggestions? has someone thought about it?

thanks

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Dec 11 2017
Added on Nov 10 2017
7 comments
1,165 views