Review default RDS port use

Review the default RDS port against operational policy, and protect the database with network restrictions, authentication and TLS.

Description

An RDS engine’s default port is a normal service setting, not a vulnerability by itself. A different port may reduce simple discovery attempts, but it does not replace network access controls or database authentication.

Potential impact

Broad access and inadequate authentication or permissions can expose or alter data regardless of the port number. Changing the port without preparation can interrupt application connections.

Remediation

Restrict security groups to required clients and apply suitable authentication, least privilege and TLS. If policy requires a custom port, choose a value supported by the engine, update clients, security groups and monitoring together, and review the change set and disruption effects.

Examples

These excerpts compare Oracle ports only. Supply a supported DBInstanceClass, storage and licensing settings separately. Provide MasterUserPassword through an appropriate secret-supply mechanism, such as a NoEcho input, rather than hardcoding it in the template.

Before

yaml
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    Properties:
      Engine: oracle-ee
      DBInstanceClass: !Ref DBInstanceClass
      MasterUsername: master
      MasterUserPassword: !Ref MasterUserPassword
      BackupRetentionPeriod: 7
      Port: 1521

This uses the default Oracle port 1521. The port alone does not establish actual access permissions.

After

yaml
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    Properties:
      Engine: oracle-ee
      DBInstanceClass: !Ref DBInstanceClass
      MasterUsername: master
      MasterUserPassword: !Ref MasterUserPassword
      BackupRetentionPeriod: 7
      Port: 1522

This changes the port to 1522. It does not reduce database permissions or network access scope.

References