Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0004080Openbravo ERPC. Securitypublic2008-06-19 16:582008-06-19 17:07
pjuvara 
alostale 
normalmajorhave not tried
closedno change required 
5
2.35 
2.40alpha-r3 
No
Core
No
0004080: Openbravo database schame has dba privileges
The Openbravo installation grants to the Oracle user housing the Openbravo schema (TAD by default) DBA privileges.

This is a security vulnerability because if hackers manage to get access to this user, they will gain control of the full database.

This is a particularly serious concern for those customers who deploy Openbravo in an Oracle database that houses other applications as well.
Connect to Oracle and verify privileges.
No tags attached.
blocks defect 00001242.40 closed alostale Openbravo database schame has dba privileges 
Issue History
2008-06-19 16:58cromeroNew Issue
2008-06-19 16:58cromeroAssigned To => alostale
2008-06-19 16:58cromeroStatusnew => scheduled
2008-06-19 16:58cromeroResolutionopen => open
2008-06-19 16:58cromeroFixed in Version => 2.40alpha-r3
2008-06-19 17:07pjuvaraStatusscheduled => closed
2008-06-19 17:07pjuvaraNote Added: 0007877
2008-06-19 17:07pjuvaraResolutionopen => no change required

Notes
(0007877)
pjuvara   
2008-06-19 17:07   
This issue is too risky to be backported and it introduces too big of a change to existing customers. Will only be fixed in the next release (2.40).