SAP ASE leaves sensitive credentials in installation logs

SAP ASE leaves sensitive credentials in installation logs

SAP users should deploy the patches for Adaptive Server Enterprise (ASE) released last month because the server fails to clear credentials from persistent installation logs. Even though the credentials are encrypted or hashed, researchers warn that attackers can easily decrypt them to gain full access to a sensitive monitoring component.

[ Keep up with 8 hot cyber security trends (and 4 going cold). Give your career a boost with top security certifications: Who they're for, what they cost, and which you need. | Sign up for CSO newsletters. ]

Previously known as Sybase SQL Server, the SAP Adaptive Server Enterprise (ASE) is a high-performance relational database with on-premises and cloud deployment options. The product is used by over 30,000 organizations worldwide, including over 90% of the world's top 50 banks.

To read this article in full, please click here



Support the originator by clicking the read the rest link below.