Software Updates

Database Security Knowledgebase Update 5.36

Written by | Dec 20, 2018 7:28:00 AM

Knowledgebase version 5.36 includes new checks for Microsoft SQL Server and MongoDB. It has updated checks for IBM Db2 LUW. It has also introduced the DISA-STIG MongoDB EA 3.x V1R1 policy as well as updated several existing policies.

New Vulnerability and Configuration Check Highlights

Microsoft SQL Server

  • Microsoft SQL Server 2014 SP3 not installed
    • Verify that Microsoft SQL Server 2014 SP3 is installed.
    • Risk: High
  • Privilege to execute sp_send_dbmail granted to PUBLIC
    • Check that permissions to execute the sp_send_dbmail procedure have not been granted to the PUBLIC role.
    • Risk: High
  • Privilege to execute sp_send_dbmail granted to user
    • Check that permissions to execute the sp_send_dbmail procedure have not been granted directly to users.
    • Risk: Medium

MongoDB

  • Ensure option ldapUserCacheInvalidationInterval is within an appropriate range
    • Verify that the Mongo configuration option setParameter.ldapUserCacheInvalidationInterval value is within the appropriate range.
    • Risk: Medium
  • Ensure that certain ssl options are configured properly
    • Verify that the following MongoDB options are configured properly: net.ssl.allInvalidCertificates is DISABLE, net.ssl.CAFile is populated, thus ENABLED
    • Risk: Medium
  • Ensure that the security option redactClientLogData is configured properly
    • Verify that the MongoDB option security.redactClientLogData is DISABLED.
    • Risk: Medium
  • Ensure the configuration file permissions are correct
    • Verify that the MongoDB configuration file and directory permissions are set accordingly.
    • Risk: Medium
  • Review Users
    • Verify that the users within the MongoDB database are authorized.
    • Risk: Medium

Updated Checks

IBM Db2 LUW

  • Fix Pack not installed on time
    • Support 11.1 Mod 4 Fix Pack 4
    • Risk: High
  • Latest Fix Pack not installed
    • Support 11.1 Mod 4 Fix Pack 4
    • Risk: High 

New Policies

  • DISA-STIG MongoDB EA 3.x V1R1 - Audit (Built-in)
    • This policy has been created with the guidelines mapped out in the DOD Security Technical Implementation Guides " MongoDB Enterprise Advance 3.x Security Technical Implementation Guide Version 1 Release 1".

Updated Policies

  • Base Line - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
      • Microsoft SQL Server: Privilege to execute sp_send_dbmail granted to PUBLIC: High
      • Microsoft SQL Server: Privilege to execute sp_send_dbmail granted to user: Medium
  • Basel II - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Best Practices for Federal Gov. - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • CIS Benchmark - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • CIS v1.0.0 for SQL Server 2014 - Audit (Built-in)
    • New Checks
      •  Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • CIS v2.0.0 for SQL Server 2005 - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2008 SP4 not installed: High
  • CNIL - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • DISA-STIG Database Security - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Database Best Practices
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Download - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • EU Data Protection Directive - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • FISMA - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • FedRAMP - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Gramm-Leach-Bliley Act - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • HIPAA - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Integrity - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
    • MITS - Audit (Built-in)
      • New Checks
        • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Massachusetts 201 CMR 17.00
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • MiFID - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • PCI Data Security Standard - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Sarbanes-Oxley - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
  • Strict - Audit (Built-in)
    • New Checks
      • Microsoft SQL Server: Microsoft SQL Server 2014 SP3 not installed: High
      • Microsoft SQL Server: Privilege to execute sp_send_dbmail granted to PUBLIC: High
      • Microsoft SQL Server: Privilege to execute sp_send_dbmail granted to user: Medium
      • MongoDB: Ensure option ldapUserCacheInvalidationInterval is within an appropriate range: Medium
      • MongoDB: Ensure that certain ssl options are configured properly: Medium
      • MongoDB: Ensure that the security option redactClientLogData is configured properly: Medium
      • MongoDB: Ensure the configuration file permissions are correct: Medium
      • MongoDB: Review Users: Medium 

User Creation Scripts

  • None this release

Availability

  • Available to all AppDetectivePRO and DbProtect customers with maintenance (subscription or perpetual) in good standing at no additional cost.
  • AppDetectivePRO customers can use the Updater within the product as well