|
From: Dimitry S. <sd...@ib...> - 2016-05-20 11:41:18
|
20.05.2016 13:26, Adriano dos Santos Fernandes wrote: > here are more reasons, but a great one is: > > Users can only read his own stored binary classes in FB/Java tables, but > can use (run) others users classes stored in the same database. As long as they have permission for it granted by other user, right? So, there is no reason to use attachment with more privileges than user already has. > FB/Java module can read all classes with his own attachment. This is a security breach. -- WBR, SD. |