Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
Normal
-
Security
Description
The NetServlet does not require credentials in order to bring the server up and down (or for any operations for that matter). See DERBY-5401. This lack of security makes the NetServlet unsuited for production use. We should document that NetServlet is only appropriate for testing purposes.
Attachments
Attachments
Issue Links
- relates to
-
DERBY-5401 The NetServlet should require system administrator credentials in order to perform its operations on a server which requires authentication.
- Open