Description
An RDS engine’s default port is a normal service setting, not a vulnerability by itself. A different port may reduce simple discovery attempts, but it does not replace network access controls or database authentication.
Potential impact
Broad access and inadequate authentication or permissions can expose or alter data regardless of the port number. Changing the port without preparation can interrupt application connections.
Remediation
Restrict security groups to required clients and apply suitable authentication, least privilege and TLS. If policy requires a custom port, choose a value supported by the engine, update clients, security groups and monitoring together, and review the change set and disruption effects.
Examples
These excerpts compare Oracle ports only. Supply a supported DBInstanceClass, storage and licensing settings separately. Provide MasterUserPassword through an appropriate secret-supply mechanism, such as a NoEcho input, rather than hardcoding it in the template.
Before
Resources:
MyDB:
Type: AWS::RDS::DBInstance
Properties:
Engine: oracle-ee
DBInstanceClass: !Ref DBInstanceClass
MasterUsername: master
MasterUserPassword: !Ref MasterUserPassword
BackupRetentionPeriod: 7
Port: 1521
This uses the default Oracle port 1521. The port alone does not establish actual access permissions.
After
Resources:
MyDB:
Type: AWS::RDS::DBInstance
Properties:
Engine: oracle-ee
DBInstanceClass: !Ref DBInstanceClass
MasterUsername: master
MasterUserPassword: !Ref MasterUserPassword
BackupRetentionPeriod: 7
Port: 1522
This changes the port to 1522. It does not reduce database permissions or network access scope.