Sun JDK can expose passwords in EAServer

An issue stemming from a bug in the Sun JDK version 1.4.2 on UNIX and Linux platforms can expose passwords used in various scenarios to risk being discovered.

EAServer Manager displays connection caches that have passwords in them. Under normal circumstances, these passwords are hidden, however, due to a security issue in JDK 1.4.2, a user with guest permission to EAServer Manager can discover the password stored in a connection cache. This password can be used to gain unauthorized access to a protected database. EAServer 5.2 and 5.3, and products that embed them, are affected by this issue.

Download and install the appropriate Sybase EBF files listed in Table 1 to address this problem.

Table 1: EBF numbers for EAServer and RTDS

Product

Version

Platform

EAS version

EBF no.

EAServer

5.2

Solaris

N/A

13238

EAServer

5.2

Linux

N/A

13507

EAServer

5.2

AIX

N/A

13508

EAServer

5.2

HP-UX

N/A

13509