It is likely that the permissions for the database are wide open, meaning any user can do anything. The DB should be audited to ensure the permissions are setup to something that would be appropriate and defensible.
There are no Sub-Tasks for this issue.