Home > SAP News > SAP, MySQL patch critical database flaw
SAP News:
EMAIL THIS LICENSING & REPRINTS

SAP, MySQL patch critical database flaw

By SearchSAP.com Staff
31 Aug 2006 | SearchSAP.com

SAP news, tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Developers have corrected a flaw in the SAP MaxDB database that could be targeted by hackers to execute arbitrary code.

Researcher Oliver Karow of Symantec is credited with finding the database vulnerability. The flaw was fixed in the latest version of MaxDB 7.6.00.31.

"It is possible to execute arbitrary code with the privileges of the 'wahttp' process by sending a malformed HTTP request. Authentication is not required for successful exploitation to occur," according to a security advisory issued by Symantec.

As a temporary workaround, MaxDB customers can disable the SAP-DB WWW Service or restrict access to it, according to Symantec. SAP customers can download the latest version at www.service.sap.com.

In 2004, SAP entered into an agreement with open source database maker MySQL to cross-license SAP DB. The open source database was then rebranded MaxDB. It is optimized to run in conjunction with the mySAP Business Suite and the MySQL database management system.

Tags: SAP securityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google




SAP Training & Employment
HomeNewsTopicsBlogsTipsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
SearchSAP.com is a search service provided by TechTarget and is completely
independent of and not affiliated with SAP AG.
  TechTarget - The IT Media ROI Experts