SAP patches ASE database login flaw

Combined with other flaws, it could allow complete access to a database


SAP patched a flaw on Thursday that could allow an attacker to take complete control over a database, according to security vendor Trustwave.

The flaw (CVE-2014-6284) affects SAP's Adaptive Server Enterprise (ASE), a relational database for Unix, Linux and Windows systems, designed for high volumes of data-rich transactions. Vulnerable versions are 12.5, 15, 15.5, 15.7 and 16.

TrustWave's Martin Rakhmanov, a senior security researcher, found an error in the challenge and response mechanism used to access ASE. The account access gained is not a privileged account, but TrustWave said other flaws allow the privileges to be escalated to that of a database administrator.

"Combined with such privilege elevation vulnerabilities, this one allows complete takeover of the database server," TrustWave said in its advisory.

Trustwave published proof-of-concept code on GitHub. SAP has also released a security note, but login details are required to view it.

Send news tips and comments to Follow me on Twitter: @jeremy_kirk

The march toward exascale computers
View Comments
Join the discussion
Be the first to comment on this article. Our Commenting Policies