Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SAP R/3 with Oracle Unauthorized Data Access Vulnerability

An issue has been reported which could allow a user to compromise SAP R/3 data.

Due to a weak default installation of SAP R/3 on Oracle, connecting to the Oracle listener will enable a user to read, write and modify SAP data.

It should be noted that this issue has only been tested on Oracle, SAP R/3 runs on several databases, therefore other implementations may be affected by this issue.







 

Privacy Statement
Copyright 2008, SecurityFocus