AWS Security ChangesHomeSearch

AWS odb: Add Exascale storage vault to Oracle Database@AWS resource sharing

Service: odb · 2026-09-27 · Documentation medium

File: odb/latest/UserGuide/resource-sharing.md · Type: iam

Summary

Documents that Exascale storage vaults can now be shared across accounts in the same AWS organization via AWS RAM, and lists the cross-account permissions granted to trusted accounts (odb:CreateExadbVmCluster, odb:CreateAutonomousDatabase, odb:ListExadbVmClusters, odb:GetExascaleDbStorageVault, odb:ListExascaleDbStorageVaults).

Security assessment

The change enumerates the IAM permissions granted to trusted accounts when an Exascale storage vault is shared, which is cross-account authorization guidance. It documents a new sharing capability and its permission surface rather than fixing a specific vulnerability.

Evidence

+  * `odb:CreateExadbVmCluster`

Diff

diff --git a/odb/latest/UserGuide/resource-sharing.md b/odb/latest/UserGuide/resource-sharing.md
index 66170550f..026c339ee 100644
--- a//odb/latest/UserGuide/resource-sharing.md
+++ b//odb/latest/UserGuide/resource-sharing.md
@@ -11 +11 @@ AWS RAM integrationBenefitsHow resource sharing worksPermissions on shared resou
-With Oracle Database@AWS, you can share Exadata infrastructure and your ODB network across multiple AWS accounts in the same AWS organization. This enables you to provision infrastructure once and reuse it across trusted accounts, allowing you to reduce costs while separating responsibilities.
+With Oracle Database@AWS, you can share Exadata infrastructure, your ODB network, and your Exascale storage vault across multiple AWS accounts in the same AWS organization. This enables you to provision infrastructure once and reuse it across trusted accounts, allowing you to reduce costs while separating responsibilities.
@@ -54,0 +55,2 @@ You can share the following Oracle Database@AWS resources:
+  * Exascale storage vault
+
@@ -111,0 +114,4 @@ The following permissions are granted to trusted accounts:
+  * `odb:CreateExadbVmCluster`
+
+  * `odb:CreateAutonomousDatabase`
+
@@ -122,0 +129,16 @@ The following permissions are granted to trusted accounts:
+**For Exascale storage vault**
+    
+
+The following permissions are granted to trusted accounts:
+
+  * `odb:CreateExadbVmCluster`
+
+  * `odb:ListExadbVmClusters`
+
+  * `odb:GetExascaleDbStorageVault`
+
+  * `odb:ListExascaleDbStorageVaults`
+
+
+
+