SAP patches log-in flaw in ASE database
27 April 2015 | 0
SAP has patched a flaw that could allow an attacker to take complete control over a database, according to security vendor Trustwave.
The flaw (CVE-2014-6284) affects SAP’s Adaptive Server Enterprise (ASE), a relational database for Unix, Linux and Windows systems, designed for high volumes of data-rich transactions. Vulnerable versions are 12.5, 15, 15.5, 15.7 and 16.
TrustWave’s Martin Rakhmanov, a senior security researcher, found an error in the challenge and response mechanism used to access ASE. The account access gained is not a privileged account, but TrustWave said other flaws allow the privileges to be escalated to that of a database administrator.
“Combined with such privilege elevation vulnerabilities, this one allows complete takeover of the database server,” TrustWave said in its advisory.
Trustwave published proof-of-concept code on GitHub. SAP has also released a security note, but log-in details are required to view it.
Jeremy Kirk, IDG News Service