Re: Informix security questions
Posted in 1997
David Williams wrote: > > In article <345E3F4C.654A@bloomberg.com>, "Art S. Kagel" > <kagel@bloomberg.com> writes > >James Woodger wrote: > >> > >> I have two basic security questions about Informix: > >> > >> 1. Is it true that if a user has execute permission on a stored proc, > >> then the stored proc will be allowed to perform any table reads or > >> updates (regardless of the original user's security profile). In other > >> words, stored procedures are not "held back" by the initiating users' > >> security level. > > > >Yes. Think of the SP's permissions and ownership like an SUID program. > > I thought that was only true if you did > > CREATE DBA PROCEDURE... > > rather than > > CREATE PROCEDURE... Not exactly. If the creator of the procedure has WITH GRANT privileges on the objects (tables, columns, etc) accessed by the procedure and the procedure creator grants execute privilege on the procedure to another user, or to public, then the executing user gets the procedure creator's privileges to any objects accessed. Since the DBA has all privileges not explicitely revoked a DBA procedure can access practically any object. This is different semantically; practically the result is the same anyone executing the procedure can use it to affect objects that that user would otherwise not have permissions to access. Art S. Kagel