Trustwave Database Security Knowledgebase version 5.59 includes new checks for Couchbase and updated checks for SAP ASE and Teradata.
New Vulnerability and Configuration Check Highlights
Couchbase
- API REST endpoints do not require authentication (CVE-2020-9039)
- Risk: High
- Couchbase is vulnerable to Cross Site Request Forgery due to browser cached credentials (CVE-2020-9042)
- Risk: High
Updated Checks
SAP ASE
- Patch not applied on time
Teradata
Availability
- Available to all AppDetectivePRO and DbProtect customers with maintenance (subscription or perpetual) in good standing at no additional cost.
- AppDetectivePRO customers can use the Updater within the product as well