Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0004080
TypeCategorySeverityReproducibilityDate SubmittedLast Update
backport[Openbravo ERP] C. Securitymajorhave not tried2008-06-19 16:582008-06-19 17:07
ReporterpjuvaraView Statuspublic 
Assigned Toalostale 
PrioritynormalResolutionno change requiredFixed in Version2.40alpha-r3
StatusclosedFix in branch2.3xFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseOracleJava version
OS VersionDatabase versionAnt version
Product Version2.35SCM revisionMP1 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0004080: Openbravo database schame has dba privileges

DescriptionThe Openbravo installation grants to the Oracle user housing the Openbravo schema (TAD by default) DBA privileges.

This is a security vulnerability because if hackers manage to get access to this user, they will gain control of the full database.

This is a particularly serious concern for those customers who deploy Openbravo in an Oracle database that houses other applications as well.
Steps To ReproduceConnect to Oracle and verify privileges.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
blocks defect 00001242.40 closedalostale Openbravo database schame has dba privileges 

-  Notes
(0007877)
pjuvara (reporter)
2008-06-19 17:07

This issue is too risky to be backported and it introduces too big of a change to existing customers. Will only be fixed in the next release (2.40).

- Issue History
Date Modified Username Field Change
2008-06-19 16:58 cromero New Issue
2008-06-19 16:58 cromero Assigned To => alostale
2008-06-19 16:58 cromero Status new => scheduled
2008-06-19 16:58 cromero Resolution open => open
2008-06-19 16:58 cromero Fixed in Version => 2.40alpha-r3
2008-06-19 17:07 pjuvara Status scheduled => closed
2008-06-19 17:07 pjuvara Note Added: 0007877
2008-06-19 17:07 pjuvara Resolution open => no change required


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker