A remote authenticated attacker could render the SAP HANA Platform unavailable to other users until the next process restart due to a memory corruption vulnerability. SAP HANA DB version 1.00.73.00.389160 is affected.
Monthly Archives: November 2015
Ubuntu Security Notice USN-2788-2
Ubuntu Security Notice 2788-2 – USN-2788-1 fixed vulnerabilities in unzip. One of the security patches caused a regression when extracting 0-byte files. This update fixes the problem. Gustavo Grieco discovered that unzip incorrectly handled certain password protected archives. If a user or automated system were tricked into processing a specially crafted zip archive, an attacker could possibly execute arbitrary code. Gustavo Grieco discovered that unzip incorrectly handled certain malformed archives. If a user or automated system were tricked into processing a specially crafted zip archive, an attacker could possibly cause unzip to hang, resulting in a denial of service. Various other issues were also addressed.
SAP HANA Remote Trace Disclosure
Due to a flaw in SAP HANA DB version 1.00.73.00.389160, a remote unauthenticated attacker could read remote logs containing technical information about the system which could help to facilitate further attacks against the system.
SAP HANA TrexNet Command Execution
Using the multiple methods available in the TrexNet protocol, a remote unauthenticated attacker could execute arbitrary operating system commands, python modules, read, write and delete files and directories, read environment information and also completely shut down the SAP HANA instance. The attacker could also send TMS queries to the NameSever component, which could allow him to retrieve technical information of the remote system such as configuration files. SAP HANA Database versions 1.00 SPS10 and below are affected.
High-Risk SAP HANA Vulnerabilities Patched
Nearly two dozen critical SAP HANA vulnerabilities have been patched, including a critical misconfiguration of the TrexNet administrative interface.
TestLink 1.9.14 Cross Site Request Forgery
TestLink version 1.9.14 suffers from a cross site request forgery vulnerability.
Kaspersky Lab Survey Shows People Take Their Mobile Devices Everywhere
TestLink 1.9.14 Cross Site Scripting
TestLink version 1.9.14 suffers from a persistent cross site scripting vulnerability.
Google AdWords API PHP Client Library 6.2.0 XXE Injection
Google AdWords API PHP client library versions 6.2.0 and below suffer from an XML eXternal Entity injection vulnerability.
Google AdWords API PHP Client Library 6.2.0 Code Execution
Google AdWords API PHP client library versions 6.2.0 and below suffer from an arbitrary PHP code execution vulnerability.