SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Database)  >   SAP R/3 Vendors:   SAP
SAP sapdba Command for Informix Environment Variable Bug Lets Local Users Gain Elevated Privileges
SecurityTracker Alert ID:  1016122
SecurityTracker URL:  http://securitytracker.com/id/1016122
CVE Reference:   CVE-2006-0732, CVE-2006-2547   (Links to External Site)
Updated:  Sep 1 2009
Original Entry Date:  May 18 2006
Impact:   Execution of arbitrary code via local system, User access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): sapdba command for Informix version 700 up to patch number 100; and prior versions
Description:   Leandro Meiners of CYBSEC reported a vulnerability in SAP in the sapdba command. A local user can gain elevated privileges.

The sapdba command for Informix does not properly process environment variables. A local user to execute arbitrary commands with 'informix' user privileges.

The vendor was notified on April 20, 2006.

The original advisory is available at:

http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Local_Privilege_Escalation_in_SAP_sapdba_Command.pdf

Impact:   A local user can gain 'informix' user privileges.
Solution:   The vendor has issued a patch. Information is available in SAP note 944585.
Vendor URL:  www.sap.com/ (Links to External Site)
Cause:   Input validation error
Underlying OS:  Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), UNIX (Tru64)

Message History:   None.


 Source Message Contents

Subject:  CYBSEC - Security Pre-Advisory: Local Privilege Escalation in SAP

(The following advisory is also available in PDF format for download at:
http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Local_Privilege_Escalation_in_SAP_sapdba_Command.pdf )

CYBSEC S.A.
www.cybsec.com

Pre-Advisory Name: Local Privilege Escalation in SAP sapdba Command

Vulnerability Class: Insecure Environment Variable Handling

Release Date: 05/18/2006

Affected Applications:  
* sapdba command for Informix version prior to 700
* sapdba command for Informix version 700 up to patch number 100

Unaffected Applications: 
* sapdba command for Oracle Databases

Affected Platforms: 
* SAP with Informix on HP-UX, Solaris, AIX, TRUE64 or Linux

Local / Remote: Local

Severity: Medium

Author:  Leandro Meiners.

Vendor Status:  
* Confirmed, patch released

Reference to Vulnerability Disclosure Policy: 
http://www.cybsec.com/vulnerability_policy.pdf

Product Overview:
=================

The sapdba command is a utility provided by SAP for database
administration. Two different versions are available, one for Informix
and another for Oracle databases.

Vulnerability Description:
==========================

The sapdba command for Informix Databases was found to allow any UNIX
user to run arbitrary commands with informix rights at the shell level,
due to improper handling of environment variables.

Technical Details:
==================

Technical details will be released three months after publication of
this pre-advisory. This was agreed upon with SAP to allow their clients
to upgrade affected software prior to the technical knowledge been
publicly available. 

Impact:
=======

Any user with login access to the SAP database server having a
vulnerable version of the sapdba command can escalate privileges to
execute arbitrary commands with the rights of the informix user.  

Solutions:
==========

SAP released a patch regarding this issue. Details can be found in SAP
note 944585.

Vendor Response:
================
* 04/20/2006: Initial Vendor Contact and technical details for the
vulnerabilities sent to vendor.
* 04/26/2006: Solution provided by vendor.
* 05/18/2006: Coordinate release of pre-advisory without technical
details.
* 08/18/2006: Coordinate release of advisory with technical details.

Contact Information:
====================

For more information regarding the vulnerability feel free to contact
the author at lmeiners<at>cybsec.com. Please bear in mind that technical
details will be disclosed three months after the release of this
pre-advisory, so such questions won't be answered until then. 

For more information regarding CYBSEC: www.cybsec.com

----------------------------
Leandro Meiners
CYBSEC S.A. Security Systems
E-mail: lmeiners@cybsec.com
Tel/Fax: [54-11] 4382-1600
Web: http://www.cybsec.com
PGP-Key: http://pgp.mit.edu:11371/pks/lookup?search=lmeiners&op=index
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC