Details
-
Improvement
-
Status: Open
-
Minor
-
Resolution: Unresolved
-
None
-
None
Description
We have a lower bound of 4 for the lengths of users and passwords, but there is no upper bound for that, so a malicious user may attack by using very long user names and it would be better to have a constraint on the length.
However, generally, only DBAs have such privileges, so it would not be a very big concern.