Rick Hillegas created DERBY-6635:
------------------------------------

             Summary: OptimizerTracer.unloadTool() could be used to write 
garbage over Derby data files.
                 Key: DERBY-6635
                 URL: https://issues.apache.org/jira/browse/DERBY-6635
             Project: Derby
          Issue Type: Bug
          Components: Tools
    Affects Versions: 10.11.0.0
            Reporter: Rick Hillegas


I don't see any checks in place to prevent this method from writing its output 
file into the log or sego directories or even over service.properties. 
Fortunately, only the DBO can run this procedure by default.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to