AWS odb: Documented four new and five updated Oracle Database@AWS managed policies
Summary
Adds a September 4, 2026 entry to the AWS managed policy change log for Oracle Database@AWS: four new policies (AmazonODBAutonomousDatabaseAdmin, AmazonODBExadataVmClusterAdmin, AmazonODBExascaleStorageVaultAdmin, AmazonODBExascaleVmClusterAdmin) and updates to five existing policies (ReadOnlyAccess, FullAccess, ExadataInfrastructureAdmin, NetworkAdmin, AutonomousVmClusterAdmin), including added permissions for IAM role association on VM clusters, grant shares, outbound integrations, and removal of the `aws:CalledVia` condition from ODB network peering permissions in Amazon EC2.
Security assessment
This is IAM documentation: it records privilege changes to AWS managed policies. Notably, removing the `aws:CalledVia` condition narrows how the network-peering permissions can be invoked (only directly rather than via a calling service), and the broadened FullAccess/Admin policies add role-association and outbound-integration privileges, which have real authorization impact. However, it documents policy capability changes rather than a fixed vulnerability or incident, so it is medium rather than high.
Evidence
+ * [AWS managed policy: AmazonODBNetworkAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBNetworkAdmin) – Removed the `aws:CalledVia` condition from the ODB network peering permissions in Amazon EC2.
Diff
diff --git a/odb/latest/UserGuide/odb-manpol-updates.md b/odb/latest/UserGuide/odb-manpol-updates.md index 56141e7de..036ed1035 100644 --- a//odb/latest/UserGuide/odb-manpol-updates.md +++ b//odb/latest/UserGuide/odb-manpol-updates.md @@ -9 +9 @@ -View details about updates to AWS managed policies for Oracle Database@AWS since this service began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the Oracle Database@AWS Document history page. +View details about updates to AWS managed policies for Oracle Database@AWS since Oracle Database@AWS began tracking these changes. For automatic alerts about changes to this page, subscribe to the RSS feed on the Oracle Database@AWS Document history page. @@ -12,0 +13,16 @@ Change | Description | Date +Oracle Database@AWS managed policies – New and updated policies | Four AWS managed policies are now available for additional Oracle Database@AWS personas: + + * [AWS managed policy: AmazonODBAutonomousDatabaseAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBAutonomousDatabaseAdmin) + * [AWS managed policy: AmazonODBExadataVmClusterAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBExadataVmClusterAdmin) + * [AWS managed policy: AmazonODBExascaleStorageVaultAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBExascaleStorageVaultAdmin) + * [AWS managed policy: AmazonODBExascaleVmClusterAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBExascaleVmClusterAdmin) + +Oracle Database@AWS also updated five existing AWS managed policies: + + * [AWS managed policy: AmazonODBReadOnlyAccess](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBReadOnlyAccess) – Added permissions to list flex components and Grid Infrastructure minor versions, and to view and list Exascale storage vault resources and Exascale VM cluster resources. + * [AWS managed policy: AmazonODBFullAccess](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBFullAccess) – Added permissions to list flex components and Grid Infrastructure minor versions. Added permissions to manage Exascale storage vault resources and Exascale VM cluster resources, including attaching and detaching virtual machines. Added permissions to associate and disassociate IAM roles for VM cluster resources, manage grant shares, and update outbound integrations. Removed the `aws:CalledVia` condition from the ODB network peering permissions in Amazon EC2. + * [AWS managed policy: AmazonODBExadataInfrastructureAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBExadataInfrastructureAdmin) – Added permission to list flex components. + * [AWS managed policy: AmazonODBNetworkAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBNetworkAdmin) – Removed the `aws:CalledVia` condition from the ODB network peering permissions in Amazon EC2. + * [AWS managed policy: AmazonODBAutonomousVmClusterAdmin](./odb-security-iam-awsmanpol.html#odb-security-iam-awsmanpol-AmazonODBAutonomousVmClusterAdmin) – Added permissions to associate and disassociate IAM roles for Autonomous VM cluster resources and to update outbound integrations. + +| September 4, 2026