*PUBLIC authority to ONEWORLD user profile on IBM i
From what I have seen, Oracle says that the *PUBLIC should have *CHANGE or *ALL authority to the ONEWORLD user profile. I've also seen that the ONEWORLD profile is supposed to have *ALLOBJ special authority. Doesn't this give all of the developers the ability to submit jobs as ONEWORLD and take advantage of its *ALLOBJ special authority? It would also let developers write programs and have them owned by ONEWORLD so they can adopt ONEWORLD's authority. Wouldn't this get flagged by an auditor as a vulnerability?
Thanks,
Travis