MaxDB handshake Message Processing Denial of Service Vulnerability
Release date:
Updated on:
Affected Systems:
SAP Basis Community MaxDB 7.x
Description:
--------------------------------------------------------------------------------
MaxDB is a relational database management system compatible with ANSI SQL-92.
MaxDB has a denial of service vulnerability. A local attacker can exploit this vulnerability to cause a denial of service.
This vulnerability is caused by an error of Null Byte reference in SAP DBTech-MAXDB service (kernel.exe) when handling some login handshake packets, resulting in service crash by sending specially crafted packets sent to TCP port 7200 or 7210.
<* Source: Abdul-Aziz harsiri
Link: http://secunia.com/advisories/44525/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP Basis Community
-------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.basisconsultant.com/modules.php? Name = Downloads & d_op = viewdownload & cid = 11