# su - oracle
$ cat /etc/oratab
orcl:/oracle/app/oracle/product/11.2.0/dbhome_1:N
crm:/oracle/app/oracle/product/11.2.0/dbhome_1:N
$ echo $ORACLE_SID
orcl
$ export ORACLE_SID=crm
$ echo $ORACLE_SID
crm
$ sqlplus / as sysdba
C:\Users\sqluser> sqlplus sys/passwd@crm as sysdba
或者
C:\Users\sqluser> set oracle_sid=crm
C:\Users\sqluser> sqlplus /nolog
SQL> connect /as sysdba 或 SQL> connect sys/passwd@crm as sysdba
SQL> select name from v$database; 或 SQL> select instance_name from v$instance;
备注:先执行如下语句,筛选是否具有DBA权限的用户,如果没有(除sys/system用户外),之后的操作可忽略。
SQL> select * from dba_role_privs where GRANTED_ROLE= 'DBA';
GRANTEE GRANTED_ROLE ADM DEF
------------------------------ ------------------------------ --- ---
SYS DBA YES YES
SYSTEM DBA YES YES
SQL> select username from dba_users where account_status='OPEN';
USERNAME
------------------------------
SYS
SYSTEM
ERP
3 rows selected.
SQL> select * from dba_role_privs where GRANTEE= 'ERP';
GRANTEE GRANTED_ROLE ADM DEF
------------------------------ ------------------------------ --- ---
ERP DBA NO YES
ERP RESOURCE NO YES
ERP CONNECT NO YES
SQL> select * from dba_sys_privs where GRANTEE='ERP';
GRANTEE PRIVILEGE ADM
------------------------------ ---------------------------------------- ---
ERP CREATE ANY SYNONYM NO
ERP UNLIMITED TABLESPACE NO
ERP CREATE SESSION NO
SQL> revoke dba from ERP;
Revoke succeeded
.
2. 重新授权必要权限
SQL> grant connect,resource to ERP;
grant create view to ERP;
grant create public synonym to ERP;
grant drop public synonym to ERP;
grant unlimited tablespace to ERP;
Grant succeeded.
SQL> select * from dba_role_privs where GRANTEE= 'ERP';
GRANTEE GRANTED_ROLE ADM DEF
------------------------------ ------------------------------ --- ---
ERP CONNECT NO YES
ERP RESOURCE NO YES
SQL> select * from dba_sys_privs where GRANTEE='ERP';
GRANTEE PRIVILEGE ADM
------------------------------ ---------------------------------------- ---
ERP CREATE VIEW NO
ERP DROP PUBLIC SYNONYM NO
ERP CREATE PUBLIC SYNONYM NO
ERP UNLIMITED TABLESPACE NO
SQL> revoke DROP ANY TABLE from ERP;
Revoke succeeded.
备注:如果ADM列显示为YES表示该权限拥有WITH ADMIN OPTION(针对系统权限)或WITH GRANT OPTION(针对对象权限),需要对其权限进行回收操作,并重新授权。
举例如下:
SQL> select * from dba_role_privs where GRANTEE='ERP';
GRANTEE GRANTED_ROLE ADM DEF
------------------------------ ------------------------------ --- ---
ERP CONNECT YES YES
ERP AQ_USER_ROLE YES YES
ERP RESOURCE NO YES
SQL> revoke connect from ERP;
Revoke succeeded.
SQL> revoke AQ_USER_ROLE from ERP;
Revoke succeeded.
SQL> grant connect to ERP;
Grant succeeded.
SQL> select * from dba_role_privs where GRANTEE='ERP';
GRANTEE GRANTED_ROLE ADM DEF
------------------------------ ------------------------------ --- ---
ERP CONNECT NO YES
ERP AQ_USER_ROLE NO YES
ERP RESOURCE NO YES
SQL> select * from dba_objects where object_type like '%LINK%';