Oracle 11g、12c大量错误登陆尝试带来的数据库异常
发布时间:2020-12-12 14:07:40 所属栏目:百科 来源:网络整理
导读:APPLIES TO: Oracle Database - Enterprise Edition - Version 10.2.0.5 and laterInformation in this document applies to any platform. CAUSE A hang is possible in earlier versions of RDBMS as a result of an unpublished bug fixed in the followi
APPLIES TO: Oracle Database - Enterprise Edition - Version 10.2.0.5 and later Information in this document applies to any platform. CAUSE A hang is possible in earlier versions of RDBMS as a result of an unpublished bug fixed in the following versions: 12.1.0.1 (Base Release) 11.2.0.2 (Server Patch Set) 11.1.0.7 Patch 42 on Windows Platforms Document 9776608.8 Bug 9776608 - Hang from concurrent login to same account with a wrong password Even with this fix,numerous failed logins attempts can cause row cache lock waits and/or library cache lock waits. This was reported in: Bug 11742803 LOTS OF 'LIBRARY CACHE LOCK' DURING USER LOGON AUTHENTICATION This was closed as not a bug because there is an intentional wait when a login fails. SOLUTIONIn Oracle 11g Release 11.1.0.7,the wait is disabled unconditionally In Oracle 11g Release 2 and higher,in order to disable the wait between login failures the event 28401 needs to be explicitly enabled: The event can be set as follows: alter system set event ="28401 TRACE NAME CONTEXT FOREVER,LEVEL 1" scope=spfile; To unset the event,set as follows: SQL> Alter system set event= '28401 trace name context off' scope=spfile ; 小结:关于大量的并发的错误密码连接数据库可能会导致数据库hang、或者引起性能问题,对数据库的影响非常大,近期就遇到过这样的一个案例。当然Oracle本身这个特性是非常好的,但是在当下确实会遇到一些问题,大家可以使用event 28401禁用这个特性。但是最好是要从管理上解决掉这样的问题,从安全层面做好管控。 (编辑:李大同) 【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容! |