cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAP HANA/SUSE Linux GNU bash code injection vulnerability

Former Member
0 Likes
967

From testing our 1.00 SP81 system from HP it appears that the version of Linux has this latest vulnerability.  Has there been any news from SAP about this?  We are contacting HP support to see how to proceed but I thought I would post this as others may want to check into this.  It seems like a very severe vulnerability.

View Entire Topic
lbreddemann
Active Contributor
0 Likes

Hi Ryan

Could you please be more specific here?

What vulnerability are you referring to? Could you post a link to it?

Thanks

Lars

Former Member
0 Likes

Lars,

Below is a link from arstechnica:

The Bash vulnerability, now dubbed by some as "Shellshock," has been reportedly found in use by an active exploit against Web servers. Additionally, the initial patch for the vulnerability was incomplete and still allows for attacks to succeed, according to a new CERT alert. See Ars' latest report for further details, our initial report is below.


A google search will reveal more news on the vulnerability.  We ran the test shown on our HANA system and it revealed the vulnerability.

http://arstechnica.com/security/2014/09/bug-in-bash-shell-creates-big-security-hole-on-anything-with...

lbreddemann
Active Contributor
0 Likes

Thanks for the details!

I will forward this one to the dev-colleagues.

However, as this is not SAP HANA specific, but as the article from arstechnica states "affects anything that runs *nix" this thread better fits into the forum.

Anyway - thanks again for pointing this out.

- Lars