|
The vendor acknowledged this vulnerability and partially rectified it in release 8.1.0. LogABug of Gupta WorldWide has given the following ID to this issue. Defect ID: 77767A This bug has not been properly rectified. In the old 8.0.0 version, the BO was at 350 characters, whereas in the new version it takes 700 characters to crash the service. The bug will be rectified in May. Until then it is recommended that you must prevent unauthorized access to your SQLBase databases, because in order to perform this attack the user must have been authorized with at least CONNECT rights. This means that the default passwords for SYSADM, SYSSQL, & SYSREP are recommended to be changed. By eliminating the unauthorized access to the database, you can prevent unauthorized user from performing this attack. |