cancel
Showing results for 
Search instead for 
Did you mean: 

SAP databases and Oracle Security Alert for CVE-2012-1675

audunlea_hansen
Active Participant
0 Kudos

Hi!

Do SAP planning to release some information / guidelined for Oracle Security Alert for CVE-2012-1675?

From Oracle: http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html

That issue concerning the listener are a thing to take a look at.

For other Oracle databases at our location, we installed the fix immediate due to this risk.

Look at these 2 links for more details around the issue.

http://seclists.org/fulldisclosure/2012/Apr/204 and http://seclists.org/fulldisclosure/2012/Apr/343

Accepted Solutions (0)

Answers (3)

Answers (3)

audunlea_hansen
Active Participant
0 Kudos

As of Note 1714255 I install the fix in all my systems.

https://service.sap.com/sap/support/notes/1714255

To say this security alert not is relevant are a too easy way to handle it. I'm sorry that I didn't see the other discussion before.

Regards

Audun

stefan_koehler
Active Contributor
0 Kudos

Hello Audun,

we already have discussed this topic a few days ago.(http://scn.sap.com/thread/3168770)

Check the replies, the test case and the upcoming information.

Regards

Stefan

volker_borowski2
Active Contributor
0 Kudos

Hi,

is that one really relevant, given that a SAP database usually does not have

LOCAL_LISTENER configured and one might have tcp.invited nodes restricted to the APP Servers.

Volker