|
In our environment the profile that uses ODBC is authorised to the
stored procedures and only to the SPs.
Do any of your stored procedures call QCMDEXC?
The database is owned by a separate profile.
The stored procedures are external LANGUAGE RPGLE.
The RPGLE programs are OWNER(database) USRPRF(*OWNER)
The underlying table/views are PUBLIC(*EXCLUDE).
Do you have any user profiles with *allobj authority?
I'm not sure what you mean by the attack surface being the same for
presumably the IBM i HTTP Server - it doesn't provide any access to
QZDASOINIT Jobs - and any access to any other resource must be explicitly
configured - the default is for everything to be locked down.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.