FLASHBACK ANY TABLE
From: Kumar Madduri <ksmadduri_at_gmail.com>
Date: Wed, 18 Mar 2015 04:50:16 -0700
Message-ID: <CAHDOOG5SQekZoaAsFfmf66RbpCYYS2oGxfJWnCFwcFC4OmRzGg_at_mail.gmail.com>
Hello:
Our developers have requested flashback any table to be given to apps (in an ebusiness environment). They would not have the apps password in production. I think they are using it to build some feature in a custom app.
Regardless of their motivation, I think this is a security risk because why would a developer want this privilege in a production environment.
Date: Wed, 18 Mar 2015 04:50:16 -0700
Message-ID: <CAHDOOG5SQekZoaAsFfmf66RbpCYYS2oGxfJWnCFwcFC4OmRzGg_at_mail.gmail.com>
Hello:
Our developers have requested flashback any table to be given to apps (in an ebusiness environment). They would not have the apps password in production. I think they are using it to build some feature in a custom app.
Regardless of their motivation, I think this is a security risk because why would a developer want this privilege in a production environment.
I cant think like a hacker but it does not sound right to me. Want to confirm with the list if I am missing something ?
Thank you
Kumar
-- http://www.freelists.org/webpage/oracle-lReceived on Wed Mar 18 2015 - 12:50:16 CET