Openbravo Issue Tracking System - Openbravo ERP |
View Issue Details |
|
ID | Project | Category | View Status | Date Submitted | Last Update |
0004080 | Openbravo ERP | C. Security | public | 2008-06-19 16:58 | 2008-06-19 17:07 |
|
Reporter | pjuvara | |
Assigned To | alostale | |
Priority | normal | Severity | major | Reproducibility | have not tried |
Status | closed | Resolution | no change required | |
Platform | | OS | 5 | OS Version | |
Product Version | 2.35 | |
Target Version | | Fixed in Version | 2.40alpha-r3 | |
Merge Request Status | |
Review Assigned To | |
OBNetwork customer | No |
Web browser | |
Modules | Core |
Support ticket | |
Regression level | |
Regression date | |
Regression introduced in release | |
Regression introduced by commit | |
Triggers an Emergency Pack | No |
|
Summary | 0004080: Openbravo database schame has dba privileges |
Description | The Openbravo installation grants to the Oracle user housing the Openbravo schema (TAD by default) DBA privileges.
This is a security vulnerability because if hackers manage to get access to this user, they will gain control of the full database.
This is a particularly serious concern for those customers who deploy Openbravo in an Oracle database that houses other applications as well. |
Steps To Reproduce | Connect to Oracle and verify privileges. |
Proposed Solution | |
Additional Information | |
Tags | No tags attached. |
Relationships | blocks | defect | 0000124 | 2.40 | closed | alostale | Openbravo database schame has dba privileges |
|
Attached Files | |
|
Issue History |
Date Modified | Username | Field | Change |
2008-06-19 16:58 | cromero | New Issue | |
2008-06-19 16:58 | cromero | Assigned To | => alostale |
2008-06-19 16:58 | cromero | Status | new => scheduled |
2008-06-19 16:58 | cromero | Resolution | open => open |
2008-06-19 16:58 | cromero | Fixed in Version | => 2.40alpha-r3 |
2008-06-19 17:07 | pjuvara | Status | scheduled => closed |
2008-06-19 17:07 | pjuvara | Note Added: 0007877 | |
2008-06-19 17:07 | pjuvara | Resolution | open => no change required |