Anyone can perform a SHOWDDL USER command

Bug #1414234 reported by Roberta Marton
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Trafodion
Fix Released
High
Cliff Gray

Bug Description

Anyone can perform the following SHOWDDL commands even if they have no privileges:

SHOWDDL COMPONENT
SHOWDDL FUNCTION
SHOWDDL PROCEDURE
SHOWDDL ROLE
SHOWDDL SCHEMA
SHOWDDL SEQUENCE
SHOWDDL USER

Only users that have the appropriate privilege should be able to execute the command.

Also, support for SHOWDDL LIBRARY is missing.

Tags: sql-security
Changed in trafodion:
assignee: nobody → Roberta Marton (roberta-marton)
importance: Undecided → High
milestone: none → r1.1
tags: added: sql-security
Cliff Gray (cliff-gray)
Changed in trafodion:
assignee: Roberta Marton (roberta-marton) → Cliff Gray (cliff-gray)
Cliff Gray (cliff-gray)
Changed in trafodion:
status: New → In Progress
Revision history for this message
Paul Low (paul-low-x) wrote :

Found an issue while verifying this fix. See Bug #1427869.

Revision history for this message
Cliff Gray (cliff-gray) wrote :

Bug 1427869 fixed, this bug now complete as of change 1296.

Changed in trafodion:
status: In Progress → Fix Committed
Revision history for this message
Paul Low (paul-low-x) wrote :

verified on 0327 build

Changed in trafodion:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.