OAT SQL Trace Broken?
Posted in 2009
Topics: Security, Permissions & Auditing, Platform-Specific Issues, Third-Party Tools & Monitoring
I'm running OAT 2.23 on WinXP against IDS 11.50.FC4 on HP-UX 11.23. I've logged in as user 'informix' and configured parameters via the GUI for a user to access the SQL Trace capabilities. But when the user attempted to use SQL Trace with OAT on his PC, a series of errors ensued indicating lack of privileges and forcing me to debug the application. I finally had to: o grant resource to user in sysadmin o grant insert to user on table ph_task in sysadmin o grant select to sqltrace and sqltrace_info to user in sysmaster Weren't all these steps supposed to have been executed by the tool? Has anybody else experienced similar problems?
On Jul 21, 3:47 pm, "red_val...@yahoo.com" <red_val...@yahoo.com> wrote: > SNIP< Is the user logging in as 'informix' ? I am betting prolly not since you had to grant the perm to them. Best Guess would be that the OAT assumes the user looking at the data has the proper permissions in the sysadmin DB. Since the SQLTRACE with the HIGH option will present all of the parameters passed to placeholders as well as clear text sql, there is a big potential for exposing sensitive data to prying eyes without locking it down. Submitting a feature request for either an alarm about permissions or automated process to grant the proper permissions for this. HTH