[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-19816-8

Platform: ms-sql2000Date: (C)2013-02-19   (M)2022-10-10



Application object owner accounts for a specified database should be configured appropriately.


Parameter:

(1)From the query prompt: USE [database name] SELECT DISTINCT u.name FROM sysusers u, sysobjects o WHERE u.uid = o.uid AND u.uid NOT IN ('1', '3', '4')


Technical Mechanism:

(1) set of accounts (2) database name

CCSS Severity:CCSS Metrics:
CCSS Score : Attack Vector:
Exploit Score: Attack Complexity:
Impact Score: Privileges Required:
Severity: User Interaction:
Vector: Scope:
 Confidentiality:
 Integrity:
 Availability:
  

References:
Resource IdReference
DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010Rule ID: V0015607 Rule Title: Application objects should be owned by accounts authorized for ownership. STIG ID: DG0008 Severity: CAT II Class: Unclass


CPE    1
cpe:/a:microsoft:sql_server:2000

© SecPod Technologies