Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0000124Openbravo ERPC. Securitypublic2008-04-25 17:052017-09-20 18:37
pjuvara 
alostale 
normalmajorhave not tried
closedfixed 
5
 
2.40 
Core
No
0000124: Openbravo database schame has dba privileges
The Openbravo installation grants to the Oracle user housing the Openbravo schema (TAD by default) DBA privileges.

This is a security vulnerability because if hackers manage to get access to this user, they will gain control of the full database.

This is a particularly serious concern for those customers who deploy Openbravo in an Oracle database that houses other applications as well.
Connect to Oracle and verify privileges.
No tags attached.
depends on backport 0004080 closed alostale Openbravo database schame has dba privileges 
related to defect 0000418 closed jpabloae Openbravo database schema has dba privileges 
related to defect 0004078 closed cromero Database user on PostgreSQL should not have SuperUser privileges 
Issue History
2008-04-25 17:05pjuvaraNew Issue
2008-04-25 17:05pjuvaraStatusnew => @50@
2008-04-25 17:05pjuvaraAssigned To => cromero
2008-04-28 11:28cromeroAssigned Tocromero => alostale
2008-04-28 11:28cromeroStatus@50@ => @40@
2008-04-30 14:08cromeroStatus@40@ => scheduled
2008-05-23 15:47alostaleStatusscheduled => resolved
2008-05-23 15:47alostaleFixed in Version => trunk
2008-05-23 15:47alostaleResolutionopen => fixed
2008-05-23 15:47alostaleNote Added: 0000321
2008-05-23 15:48alostaleStatusresolved => new
2008-05-23 15:48alostaleResolutionfixed => open
2008-05-23 15:49alostaleStatusnew => scheduled
2008-05-23 15:49alostaleStatusscheduled => resolved
2008-05-23 15:49alostaleResolutionopen => fixed
2008-05-23 15:52alostaleStatusresolved => new
2008-05-23 15:52alostaleResolutionfixed => open
2008-05-23 15:52alostaleIssue cloned0000418
2008-05-23 15:52alostaleRelationship addedrelated to 0000418
2008-05-23 15:53alostaleStatusnew => scheduled
2008-05-23 15:54alostaleStatusscheduled => resolved
2008-05-23 15:54alostaleResolutionopen => fixed
2008-06-11 14:47cromeroTarget Version => 2.40
2008-06-11 14:50cromeroFixed in Versiontrunk => 2.40alpha r3
2008-06-19 16:58cromeroRelationship addedrelated to 0004078
2008-06-19 16:58cromeroStatusresolved => new
2008-06-19 16:58cromeroResolutionfixed => open
2008-06-19 16:58cromeroNote Added: 0007876
2008-06-19 16:58cromeroStatusnew => scheduled
2008-06-19 16:59cromeroStatusscheduled => resolved
2008-06-19 16:59cromerosvn_revision => 4497
2008-06-19 16:59cromeroResolutionopen => fixed
2008-07-01 17:56anonymoussf_bug_id0 => 2007862
2008-07-10 11:52plujanStatusresolved => closed
2008-07-10 11:52plujanFixed in Version2.40alpha-r3 => 2.40beta
2017-08-01 03:31hgbotCheckin
2017-08-01 03:31hgbotNote Added: 0098284
2017-08-01 03:31hgbotStatusclosed => resolved
2017-08-01 03:31hgbotFixed in SCM revision4497 => http://code.openbravo.com/erp/pmods/org.openbravo.customer.relationshipmanagement/rev/4c0155268f0fbe201ca2c4eb9de98665a6f7ab11 [^]
2017-08-04 09:32alostaleNote Added: 0098382
2017-08-04 09:32alostaleStatusresolved => closed
2017-08-04 09:32alostaleFixed in Version2.40beta =>
2017-09-20 18:37umartirenaTriggers an Emergency Pack => No
2017-09-20 18:37umartirenaversion2.35 =>
2017-09-20 18:37umartirenaFixed in SCM revisionhttp://code.openbravo.com/erp/pmods/org.openbravo.customer.relationshipmanagement/rev/4c0155268f0fbe201ca2c4eb9de98665a6f7ab11 [^] =>
2017-09-20 18:37umartirenaNote Deleted: 0098284

Notes
(0000321)
alostale   
2008-05-23 15:47   
Fixed for create database from xml files
r4497.
(0007876)
cromero   
2008-06-19 16:58   
Backport necessary
(0098382)
alostale   
2017-08-04 09:32   
closing incorrectly reopened issue