Lucene search

K
symantecSymantec Security ResponseSMNTC-111131
HistoryDec 10, 2019 - 12:00 a.m.

SAP Adaptive Server Enterprise CVE-2019-0402 Information Disclosure Vulnerability

2019-12-1000:00:00
Symantec Security Response
www.symantec.com
19

EPSS

0

Percentile

12.6%

Description

SAP Adaptive Server Enterprise is prone to an unspecified information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may lead to further attacks. SAP Adaptive Server Enterprise versions 15.7 and 16.0 are vulnerable.

Technologies Affected

  • SAP Adaptive Server Enterprise 15.7
  • SAP Adaptive Server Enterprise 16.0

Recommendations

Block external access at the network boundary, unless external parties require service.
If global access isn’t needed, filter access to the affected computer at the network boundary. Restricting access to only trusted computers and networks might greatly reduce the likelihood of successful exploits.

Deploy network intrusion detection systems to monitor network traffic for malicious activity.
Deploy NIDS to detect and block attacks and anomalous activity such as requests containing suspicious URI sequences. Since the webserver may log such requests, review its logs regularly.

Run all software as a nonprivileged user with minimal access rights.
To limit the consequences of successful exploits, run server processes within a restricted environment using facilities such as chroot or jail.

Updates are available. Please see the references or vendor advisory for more information.

References

EPSS

0

Percentile

12.6%

Related for SMNTC-111131