Educause Security Discussion mailing list archives

Re: ODBC Access to Oracle


From: Theresa Rowe <rowe () OAKLAND EDU>
Date: Wed, 15 Aug 2018 10:58:13 -0400

We allow reporting access via ODBC to Banner.  In fact it is still our
primary report development tool.  We do not review the report development
prior to use in production.  We do not allow any table updates of any kind
using this method.  It is read-only.

Theresa

On Wed, Aug 15, 2018 at 10:18 AM George J. Silowash <gsilowas () norwich edu>
wrote:

Hello,



I am currently researching the security implications of allowing ODBC
access to an Oracle database, in particular, Ellucian Banner.  I have a
user requesting ODBC access to the Banner database. My gut feeling is to
prohibit this access, but I need more information.



Does anyone have best practices for implementing this? Or, what are the
reasons for prohibiting access? I am most concerned about:



-Data integrity

-Access control of tables and fields

-Accidental database denial of service (a query that is not constrained
appropriately, etc.)



Is Oracle security enforced on an ODBC connection? Some research on other
applications implies that it is not. Any help or guidance would be greatly
appreciated.



Regards,

George

----------------------------------------------------------------

*George J. Silowash, MSIA, CISSP-ISSMP, CCFP, GCFE*

*Chief Information Security Officer*

Norwich University

158 Harmon Drive

Northfield VT 05663

http://www.norwich.edu







-- 
Theresa Rowe
Chief Information Officer
Oakland University

Current thread: