Page 1 of 1

Ascential DataStage Multiple Security Issues

Posted: Thu Aug 31, 2017 5:07 am
by JoeClark
Ryan NA has reported some security issues in Ascential DataStage, which can be exploited by malicious, local users to disclose sensitive information and to manipulate certain data, and by malicious users to disclose sensitive information.

1) The dsjob parameters are specified on the command line, which can be exploited e.g. to disclose passwords.

2) Insecure file permissions under the installation directory and the project directory can be exploited to manipulate certain files.

3) Additional logging output options include passwords within the log files.

The security issues are reported in version 7.5. Other versions may also be affected.



I didn't find the right solution from the internet.

Posted: Thu Aug 31, 2017 5:59 am
by chulett
Okay. :?

Hasn't been "Ascential" DataStage in a long time, never mind the fact that your posts just seem like a mechanism to advertise... something. I removed your URL as that's not why we're here.

Posted: Thu Aug 31, 2017 6:14 am
by qt_ky
That's really, really old information...

Posted: Thu Aug 31, 2017 6:39 am
by chulett
ps. I deleted the completely off-topic second advertising post in the TX forum.

Re: Ascential DataStage Multiple Security Issues

Posted: Thu Aug 31, 2017 7:14 am
by Thomas.B
JoeClark wrote:I didn't find the right solution from the internet.
The solution was right under the text you copy / paste from cnet.