|
AppDetective™ Update 5.0.3 - 28 February 2005
ENHANCEMENTS
IBM DB2 - NEW CHECKS
- Arbitrary code execution when processing connection messages
Examines if the database is vulnerable to attacks involving connection messages
Risk Level - High
- Arbitrary code execution in a federated system
Examines if the database is vulnerable to several federated system attacks
Risk Level - High
- Arbitrary code execution when using SELECT with XML functions
Examines if the database is vulnerable to arbitrary code execution when using SELECT with XML functions
Risk Level - High
IBM DB2 on Mainframe - CHECK ENHANCEMENTS
- Enhancements to Access Control Security Audit checks
Sybase - CHECK ENHANCEMENTS
- Off-line Password Cracking Enhancements to Identification/Password Control Security Audit checks for Increased Performance
UPDATED CHECKS
- Updates to "Latest Patch Not Applied" checks
- Sybase - Updates to "Multiple Vulnerabilities in Sybase ASE" check
- IBM DB2 - Updates to "Arbitrary file creation in XML Extender functions" and "Improper permissions on DB2 resources" checks
Return to ASAP™ Updates Listing
|