Having the database on a seperate server doesn't imply it's safe, if the web application has access to the database.
If you are new to web application security, OWASP is a good starting point: https://www.owasp.org/index.php/Main_Page
If you are new to web application security, OWASP is a good starting point: https://www.owasp.org/index.php/Main_Page