Application Security Inc. - Database Security, Monitoring, Assessment, Auditing, Encryption, and Regulatory Compliance.
 
 
 
home client login partner login purchasing info contact us
search:
Solutions Products Partners Support News & Events About Us
AppSec Inc Support

Security Updates - ASAP™ Updates
(Application Security Automatic Protection)

ASAP Update: 10 October 2008

ENHANCEMENTS IN THIS ASAP UPDATE INCLUDE:


ORACLE
  • NEW! Oracle Account Root Privileges
    Examines if the Oracle installation account's group is properly set.
    Risk Level - Medium

  • NEW! BECOME USER privilege escalation via KUPP$PROC
    Examines for accounts (other than DBA, SYS, and SYSTEM) that have been granted privileges: BECOME USER, execution towards KUPP$PROC.CHANGER_USER and CREATE SESSION
    Risk Level - Medium

MICROSOFT SQL SERVER
  • NEW! 'sa' account has not been disabled
    Examines if the sa login account is disabled.
    Risk Level - Low

IBM DB2
  • UPDATED! Latest FixPak not installed
    Examines for FP2 released for version 9.5
    Risk Level - High