Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the sue domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the shortcodes-ultimate domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the complianz-gdpr domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php on line 6114

Deprecated: Creation of dynamic property EDD_Theme_Updater_Admin::$item_name is deprecated in /www/htdocs/w01a7138/opendb.de/wp-content/themes/mh-magazine/includes/updater/theme-updater-admin.php on line 54

Deprecated: Creation of dynamic property EDD_Theme_Updater_Admin::$beta is deprecated in /www/htdocs/w01a7138/opendb.de/wp-content/themes/mh-magazine/includes/updater/theme-updater-admin.php on line 60

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /www/htdocs/w01a7138/opendb.de/wp-includes/functions.php:6114) in /www/htdocs/w01a7138/opendb.de/wp-includes/rest-api/class-wp-rest-server.php on line 1893
{"id":90,"date":"2005-04-27T14:13:27","date_gmt":"2005-04-27T12:13:27","guid":{"rendered":""},"modified":"2021-02-10T00:06:06","modified_gmt":"2021-02-09T23:06:06","slug":"sicherheitsluecken-datenbank-maxdb_90","status":"publish","type":"post","link":"https:\/\/opendb.de\/maxdb-sap_db\/sicherheitsluecken-datenbank-maxdb_90\/","title":{"rendered":"Sicherheitsl\u00fccken in Datenbank MaxDB"},"content":{"rendered":"

Der Sicherheitsdienstleister iDefense hat zwei Sicherheitsl\u00fccken in der Datenbank MaxDB gemeldet, mit denen es m\u00f6glich ist, ein System zu infiltrieren — in der normalen Konfiguration, in der die Administrationstools nicht zur Nutzung \u00fcber das Internet eingerichtet sind, l\u00e4sst sich dies allerdings nur \u00fcber das LAN ausnutzen.<\/p>\n

Beide Fehler finden sich in der Web-Funktion zur Administration des Servers. So f\u00fchrt ein bestimmter GET-Request mit einem Prozentzeichen und einer langen Zeichenkette zu einem Puffer\u00fcberlauf, den ein Angreifer ausnutzen kann, um Code in ein System zu schleusen und mit System-Rechten auszuf\u00fchren. Zudem verursacht ein pr\u00e4parierter GET-Request an den WebDAV-Dienst (Lock-Token) einen Buffer Overflow, mit dem sich ebenfalls Code in den Server einbringen und starten l\u00e4sst.<\/p>\n

Die Fehler finden sich in den Versionen 7.5.00.24 und fr\u00fcheren Versionen und sind in Version 7.5.00.26 behoben. Version 7.5.00.25 wurde von den Entwicklern offenbar \u00fcbersprungen. Als Workaround empfiehlt iDefense, den Zugriff auf administrative Dienste durch Filter zu beschr\u00e4nken.<\/p>\n

iDefense weist in einem dritten Advisory auf einen weiteren Fehler hin. GET-Requests mit einem Unlock-Token an den WebDAV-Dienst k\u00f6nnen ebenfalls zu einem Buffer Overflow f\u00fchren, wenn ein zu langer IF-Parameter \u00fcbergeben wird.<\/p>\n

Quelle: http:\/\/www.heise.de\/newsticker\/meldung\/58999<\/a><\/p>","protected":false},"excerpt":{"rendered":"

Der Sicherheitsdienstleister iDefense hat zwei Sicherheitsl\u00fccken in der Datenbank MaxDB gemeldet, mit denen es m\u00f6glich ist, ein System zu infiltrieren — in der normalen Konfiguration, in der die Administrationstools nicht zur Nutzung \u00fcber das Internet eingerichtet sind, l\u00e4sst sich dies allerdings nur \u00fcber das LAN ausnutzen.<\/p>\n

[…]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":{"0":"post-90","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-maxdb-sap_db"},"_links":{"self":[{"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/posts\/90","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/comments?post=90"}],"version-history":[{"count":0,"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/posts\/90\/revisions"}],"wp:attachment":[{"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/media?parent=90"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/categories?post=90"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/opendb.de\/wp-json\/wp\/v2\/tags?post=90"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}