<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567763#M3843622</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I try this on our Hana v70 instance, I get&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refreshing service 'susecloud'.&lt;/P&gt;&lt;P&gt;Warning: No repositories defined. Operating only with the installed resolvables. Nothing can be installed.&lt;/P&gt;&lt;P&gt;Loading repository data...&lt;/P&gt;&lt;P&gt;Reading installed packages...&lt;/P&gt;&lt;P&gt;'slessp2-bash-9736' not found in package names. Trying capabilities.&lt;/P&gt;&lt;P&gt;No provider of 'patch:slessp2-bash-9736' found.&lt;/P&gt;&lt;P&gt;Resolving package dependencies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously, no repositories are defined on that machine. Can you please specify what to do in that case? Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Micha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Sep 2014 09:56:38 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2014-09-29T09:56:38Z</dc:date>
    <item>
      <title>SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaq-p/10567754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From testing our 1.00 SP81 system from HP it appears that the version of Linux has this latest vulnerability.&amp;nbsp; Has there been any news from SAP about this?&amp;nbsp; We are contacting HP support to see how to proceed but I thought I would post this as others may want to check into this.&amp;nbsp; It seems like a very severe vulnerability.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 20:44:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaq-p/10567754</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-25T20:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567755#M3843614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ryan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please be more specific here? &lt;/P&gt;&lt;P&gt;What vulnerability are you referring to? Could you post a link to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 20:49:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567755#M3843614</guid>
      <dc:creator>lbreddemann</dc:creator>
      <dc:date>2014-09-25T20:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567756#M3843615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lars,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a link from arstechnica:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #263034; font-family: Arial, sans-serif; font-size: 14px;"&gt;The Bash vulnerability, now dubbed by some as "Shellshock," has been reportedly found in use by an active exploit against Web servers. Additionally, the initial patch for the vulnerability was incomplete and still allows for attacks to succeed, &lt;/SPAN&gt;&lt;A href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169" style="color: #699fb3; font-family: Arial, sans-serif; font-size: 14px;"&gt;according to a new CERT alert&lt;/A&gt;&lt;SPAN style="color: #263034; font-family: Arial, sans-serif; font-size: 14px;"&gt;. See&lt;/SPAN&gt;&lt;A href="http://arstechnica.com/security/2014/09/concern-over-bash-vulnerability-grows-as-exploit-reported-in-the-wild/" style="color: #699fb3; font-family: Arial, sans-serif; font-size: 14px;"&gt; Ars' latest report&lt;/A&gt;&lt;SPAN style="color: #263034; font-family: Arial, sans-serif; font-size: 14px;"&gt; for further details, our initial report is below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #263034; font-family: Arial, sans-serif; font-size: 14px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #263034; font-family: Arial, sans-serif; font-size: 14px;"&gt;A google search will reveal more news on the vulnerability.&amp;nbsp; We ran the test shown on our HANA system and it revealed the vulnerability.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://arstechnica.com/security/2014/09/bug-in-bash-shell-creates-big-security-hole-on-anything-with-nix-in-it/" title="http://arstechnica.com/security/2014/09/bug-in-bash-shell-creates-big-security-hole-on-anything-with-nix-in-it/"&gt;http://arstechnica.com/security/2014/09/bug-in-bash-shell-creates-big-security-hole-on-anything-with-nix-in-it/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 20:55:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567756#M3843615</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-25T20:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567757#M3843616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the security advisory from Novell/SUSE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.novell.com/security/cve/CVE-2014-6271.html" title="http://support.novell.com/security/cve/CVE-2014-6271.html"&gt;CVE-2014-6271&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 20:59:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567757#M3843616</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-25T20:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567758#M3843617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the details! &lt;/P&gt;&lt;P&gt;I will forward this one to the dev-colleagues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, as this is not SAP HANA specific, but as the article from arstechnica states "affects anything that runs *nix" this thread better fits into the &lt;A __default_attr="2162" __jive_macro_name="community" class="jive_macro_community jive_macro" data-orig-content="SAP on Linux" href="https://community.sap.com/"&gt;&lt;/A&gt; forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway - thanks again for pointing this out. &lt;/P&gt;&lt;P&gt;- Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 21:27:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567758#M3843617</guid>
      <dc:creator>lbreddemann</dc:creator>
      <dc:date>2014-09-25T21:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567759#M3843618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same news reached our platform team as well. Now to be safe they are updating the servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Krishna Tangudu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 04:57:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567759#M3843618</guid>
      <dc:creator>former_member182302</dc:creator>
      <dc:date>2014-09-26T04:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567760#M3843619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just received info from my colleagues in the SAP Linux Labs:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; patches are already available, please see&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;A href="http://support.novell.com/security/cve/CVE-2014-0475.html"&gt;http://support.novell.com/security/cve/CVE-2014-0475.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; SUSE Linux Enterprise Server 11 SP3:&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; zypper in -t patch slessp3-bash-9740&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; SUSE Linux Enterprise Server 11 SP2 LTSS:&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; zypper in -t patch slessp2-bash-9736&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; SUSE Linux Enterprise Server 11 SP1 LTSS:&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; zypper in -t patch slessp1-bash-9738&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; &lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; Red Hat Enterprise Linux 6.5&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; yum update bash-4.1.2-15.el6_5.1&lt;/P&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 17:46:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567760#M3843619</guid>
      <dc:creator>lbreddemann</dc:creator>
      <dc:date>2014-09-26T17:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567761#M3843620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Lars!&amp;nbsp; We have a case open with our HANA vendor, as they asked us to contact them for Linux updates.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 17:52:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567761#M3843620</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-26T17:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567762#M3843621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do note that the fix provided in patch 9740/9736/9738 for bash on SuSE is not a full patch. It prevents the immediate severe bug [1], but exposes another [2] related vulnerability. Apply the patch right away, but please keep monitoring the Novell advisories.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ninad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[1] - &lt;A href="http://support.novell.com/security/cve/CVE-2014-6271.html" title="http://support.novell.com/security/cve/CVE-2014-6271.html"&gt;http://support.novell.com/security/cve/CVE-2014-6271.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[2] - &lt;A href="http://support.novell.com/security/cve/CVE-2014-7169.html" title="http://support.novell.com/security/cve/CVE-2014-7169.html"&gt;CVE-2014-7169&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 19:03:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567762#M3843621</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-26T19:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567763#M3843622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I try this on our Hana v70 instance, I get&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refreshing service 'susecloud'.&lt;/P&gt;&lt;P&gt;Warning: No repositories defined. Operating only with the installed resolvables. Nothing can be installed.&lt;/P&gt;&lt;P&gt;Loading repository data...&lt;/P&gt;&lt;P&gt;Reading installed packages...&lt;/P&gt;&lt;P&gt;'slessp2-bash-9736' not found in package names. Trying capabilities.&lt;/P&gt;&lt;P&gt;No provider of 'patch:slessp2-bash-9736' found.&lt;/P&gt;&lt;P&gt;Resolving package dependencies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously, no repositories are defined on that machine. Can you please specify what to do in that case? Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Micha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 09:56:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567763#M3843622</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-29T09:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567764#M3843623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Micha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was not successful with that command either, but the following commands helped me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zypper list-patches | grep bash&lt;/P&gt;&lt;P&gt;zypper search -t patch slessp3-bash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove the patch number at the end, and you will see a list of patches (I was testing on a SP3 box, hence the sp3 above). Installing those patches should also be similar, please check the SuSE documentation!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 11:55:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567764#M3843623</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-29T11:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567765#M3843624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, this does not work either, I've already tried:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# zypper list-patches &lt;/P&gt;&lt;P&gt;Refreshing service 'susecloud'.&lt;/P&gt;&lt;P&gt;Loading repository data...&lt;/P&gt;&lt;P&gt;Reading installed packages...&lt;/P&gt;&lt;P&gt;No updates found.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Micha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 12:09:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567765#M3843624</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-29T12:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567766#M3843625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Micha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry - but what repositories need to be setup for these systems has to be defined by the Linux admin/the hardware provider for SAP HANA.&lt;/P&gt;&lt;P&gt;My best guess is that you need to have a proper support contract for this SLES server - with that you can access the online update repositories for the SLES enterprise server updates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 15:54:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567766#M3843625</guid>
      <dc:creator>lbreddemann</dc:creator>
      <dc:date>2014-09-29T15:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567767#M3843626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lars,&lt;/P&gt;&lt;P&gt;this is an AWS instance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Micha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 16:27:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567767#M3843626</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-09-29T16:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567768#M3843627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry - no idea on how the SLES support is set up for those. &lt;/P&gt;&lt;P&gt;- Lars&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2014 20:48:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567768#M3843627</guid>
      <dc:creator>lbreddemann</dc:creator>
      <dc:date>2014-09-29T20:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567769#M3843628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Micha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;some basic testing, can you resolve the hostname from your HANA host?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;default-ec2-update.susecloud.net&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;depending on your SLES version you repository will be picked up if configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your unable to resolve the hostname, then you have a DNS issue.&lt;/P&gt;&lt;P&gt;-Jochen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:21:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567769#M3843628</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-10-03T14:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567770#M3843629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jochen,&lt;/P&gt;&lt;P&gt;no thank you, we have no DNS problem, I would know about it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; No repository is configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# zypper repos&lt;/P&gt;&lt;P&gt;No repositories defined. Use the 'zypper addrepo' command to add one or more repositories.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is just one service, to which we have no password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# zypper ref -s&lt;/P&gt;&lt;P&gt;Refreshing service 'nu_novell_com'.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Authentication required for '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://nu.novell.com/?credentials=NCCcredentials"&gt;https://nu.novell.com/?credentials=NCCcredentials&lt;/A&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;User Name: bc599208a29b4b92b33fe580ccb54edf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Micha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:35:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567770#M3843629</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-10-03T14:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: SAP HANA/SUSE Linux GNU bash code injection vulnerability</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567771#M3843630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Micha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using AWS, but used a cloud formation template to build HANA, see attached repo file&lt;/P&gt;&lt;P&gt;-Jochen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:52:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-hana-suse-linux-gnu-bash-code-injection-vulnerability/qaa-p/10567771#M3843630</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-10-03T14:52:45Z</dc:date>
    </item>
  </channel>
</rss>

