SAP R/3 with Oracle Unauthorized Data Access Vulnerability
BID:4613
Info
SAP R/3 with Oracle Unauthorized Data Access Vulnerability
| Bugtraq ID: | 4613 |
| Class: | Design Error |
| CVE: |
CVE-2002-1578 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Jochen Hein <[email protected]>. |
| Vulnerable: |
SAP SAP R/3 0 |
| Not Vulnerable: | |
Discussion
SAP R/3 with Oracle Unauthorized Data Access Vulnerability
An issue has been reported which could allow a user to compromise SAP R/3 data.
Due to a weak default installation of SAP R/3 on Oracle, connecting to the Oracle listener will enable a user to read, write and modify SAP data.
It should be noted that this issue has only been tested on Oracle, SAP R/3 runs on several databases, therefore other implementations may be affected by this issue.
An issue has been reported which could allow a user to compromise SAP R/3 data.
Due to a weak default installation of SAP R/3 on Oracle, connecting to the Oracle listener will enable a user to read, write and modify SAP data.
It should be noted that this issue has only been tested on Oracle, SAP R/3 runs on several databases, therefore other implementations may be affected by this issue.
Exploit / POC
SAP R/3 with Oracle Unauthorized Data Access Vulnerability
Jochen Hein <[email protected]> has provided an exploit for this issue. Please note that it is written in German:
http://www.lan-ks.de/~jochen/sap-r3/ora-hack.html
Jochen Hein <[email protected]> has provided an exploit for this issue. Please note that it is written in German:
http://www.lan-ks.de/~jochen/sap-r3/ora-hack.html
Solution / Fix
SAP R/3 with Oracle Unauthorized Data Access Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.