Recently, SAP developers have fixed a critical vulnerability in the SAP MaxDB database, which can be exploited by hackers to execute malicious code.
Symantec researchers Olive Karow discovered the database vulnerability. This vulnerability is fixed in the latest version of MaxDB 7.6.00.31.
According to Symantec's report, "by sending a deformed HTTP request, attackers can obtain wahttp process permissions and execute malicious code. This vulnerability can be successfully exploited without authentication ."
According to Symantec's report, there is a temporary solution where MaxDB customers can disable the SAP-DB's WWW service or control its access permissions. SAP customers can download the latest database version from www.service.sap.com.
In 2004, SAP reached an agreement with the open-source database MySQL to share the sap db patent, and then renamed the database MaxDB. MaxDB is optimized to run in combination with mySAP Business Suite and MySQL database management system.
Link: http://searchsap.techtarget.com/originalContent/0,289142,sid21_gci1213576,00.html
(T114)