如本文所示,DB2 可能容易受到 SQL 注入的攻击:
* Potential SQL injection if X, Y or Z host variables come from untrusted input
STRING "INSERT INTO TBL (a,b,c) VALUES (" X "," Y "," Z ")" INTO MY-SQL.
EXEC SQL PREPARE STMT FROM :MY-SQL END-EXEC.
EXEC SQL EXECUTE STMT END-EXEC.
我的问题是本机 IMS 命令是否容易受到这种(或类似)注入的攻击?例如,通过在ISRT DLI 命令中输入恶意输入。