YarrowSoft

Темы : [cache_ru] [Cache-News] Security Advisory, Programmer Mode Role Modification : группа пользователей постреляционной СУБД Cache

Ответы 1- 1 из 1

Письмо #6194

Тема: [cache_ru] [Cache-News] Security Advisory, Programmer Mode Role Modification
Начало этой темы: [cache_ru] [Cache-News] Security Advisory, Programmer Mode Role Modification
Это ответ на: нет
Ответ на это письмо: нет
От: Andrey Grachev Дата: 02 Апреля 2008 19:55

FYI

-----Original Message-----
Sent: Tuesday, April 01, 2008 10:09 PM
To: E-Mail; E-Mail
Subject: [Cache-News] Security Advisory, Programmer Mode Role Modification


April 1, 2008 - Security Advisory, Programmer Mode Role Modification

InterSystems has corrected a security issue that
allows granting of unauthorized roles.

This defect exists in all currently released
versions of Caché starting with Caché 5.1 and for
all versions of Ensemble. The defect exists on all platforms.

InterSystems believes the risk from this defect
is low.  The unauthorized granting is only
possible from the programmer mode command line,
and most systems have already restricted
programmer mode access to trusted users.

The correction for this defect is identified as
STC1352 and is available from InterSystems as an Ad Hoc distribution.


This is an announcement mailing list for Cache'.
Cache' news, release information, and support issues from

InterSystems Corporation will be sent to this list.

The information is also posted to our website.

All the Cache' support issues announced on this list are at:

http://www.intersystems.com/support/cflash/index.html


Current release information is available at:

http://www.intersystems.com/cache/technology/product-tables/current-prodlist

..html

Now available - Ensemble-News mailing list.
You can get more information and sign up at:

http://www.intersystems.com/support/mailinglist.html


You can also sign up for our monthly e-UpDate newsletter.
In it you will find timely information about Cache' and InterSystems.
See the latest edition and sign up at:

http://www.intersystems.com/e-update



Subscription information about Cache-News is available at:

http://mail.intersystems.com/mailman/listinfo/cache-news


2010-09-03 23:07:21 - : /home/jusoft/tmp/xap/cache_simplygate_com_70.txt
2010-09-03 23:07:21 - : /home/jusoft/tmp/xap/cache_simplygate_com_70.txt
2010-09-03 23:07:21 - : /home/jusoft/tmp/xap/cache_simplygate_com_70.txt