SAP fixes flaw in ASE database
SAP on Thursday patched a flaw that could allow an attacker to take complete control of a database, according to security Trustwave.
The flaw (CVE-2014-6284) affects SAP's Adaptive Server Enterprise (ASE), a relational database for Unix, Linux, and Windows systems designed for large volumes of data-rich transactions. The vulnerable versions are 12.5, 15, 15.5, 15.7, and 16.
Martin Rakhmanov, a senior security researcher at TrustWave, found a flaw in the response mechanism used to access ASE. The account used to access it is not a privileged account, but according to TrustWave, other flaws allow privileged accounts to be transformed into database administrator accounts.
"By combining vulnerabilities like these that 'elevate' account privileges, an attacker can easily take complete control of a central database server," TrustWave points out in its advisory.
Trustwave published a proof-of-concept code on GitHub.
SAP has also published a security note, but access to it requires login details.

