Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: 9iDB Security Hole?

Re: 9iDB Security Hole?

From: Niall Litchfield <n-litchfield_at_audit-commission.gov.uk>
Date: Wed, 17 Apr 2002 09:56:30 +0100
Message-ID: <3cbd38be$0$227$ed9e5944@reading.news.pipex.net>


"Jonathan Lewis" <jonathan_at_jlcomp.demon.co.uk> wrote in message news:1018989327.14755.0.nnrp-13.9e984b29_at_news.demon.co.uk...

>

> As Howard has pointed out, if you can create
> views, you can create updatable join views,
> and then you can change or delete any
> data you want in the system.

That is the situation in 9.0.1. I'd read Pete's post as applying to 9.0.2 (beta whatever). I.E that he was saying the bug had already been fixed in 9ir2. (as opposed to slated for fix). Given that the bug appears (to my poor brain anyway) to manifest itself in a number of different ways (as you point out inline views are just fine but dictionary views aren't for example) I'd just hoped to see the exact example howard gives fail in 9.0.2. If this isn't possible though I'm fine to wait.

--
Niall Litchfield
Oracle DBA
Audit Commission UK
*****************************************
Please include version and platform
and SQL where applicable
It makes life easier and increases the
likelihood of a good answer

******************************************
Received on Wed Apr 17 2002 - 03:56:30 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US