VendorsSAPsap_db7.3.00
Vulnerabilities

SAP SAP Db 7.3.00

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2007-3614
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
Published 2007-07-06 · Modified
7.53 PoCEPSS 0.700
CVE-2002-1576
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program.
Published 2004-03-16 · Modified
7.21 PoCEPSS 0.009
CVE-2003-1033
The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.
Published 2004-03-16 · Modified
7.2EPSS 0.003
CVE-2003-1034
The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.
Published 2004-03-16 · Modified
4.6EPSS 0.003