Re: PUBLIC privileges on XDB$ACL
Date: Thu, 19 Jul 2012 08:48:47 -0500 (CDT)
> I'm trying to track down the source of a overly permissive privilege issue
> on XDB$ACL. At about Oracle 9.2 when Oracle XML Database is installed it
> seems catqm.sql (or one of its sub-scripts) executed
> "grant all on XDB.XDB$ACL to public"
In 10.1.0.5 (AIX), it's in ?/rdbms/admin/catxdbz.sql, apparently from 02/19/02 and with a comment of "Make XDB$ACL writeable by all users" immediately preceding it.
The "commit" following the GRANT is curious....
RichReceived on Thu Jul 19 2012 - 08:48:47 CDT