$Oracle applications logs publicy available

Description

Oracle SQLNet and/or listener log files are publicly accessible. The SQLNet and Listener log files provide audit data useful to the discovery of suspicious behavior. The log files may contain usernames and passwords in clear text as well as other information that could aid a malicious user with unauthorized access attempts to the database. Generation and protection of these files helps support security monitoring efforts.

Remediation

Restrict access to the listener and sqlnet log files.

References