Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-3614

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.777
EPSS Ranking 98.9%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2007-3614
  • Sap » Sap Db » Version: 7.3.00
    cpe:2.3:a:sap:sap_db:7.3.00
  • Sap » Sap Db » Version: 7.3.29
    cpe:2.3:a:sap:sap_db:7.3.29
  • Sap » Sap Db » Version: 7.4
    cpe:2.3:a:sap:sap_db:7.4
  • Sap » Sap Db » Version: 7.4.03.29
    cpe:2.3:a:sap:sap_db:7.4.03.29
  • Sap » Sap Db » Version: 7.4.03.30
    cpe:2.3:a:sap:sap_db:7.4.03.30
  • Sap » Sap Db » Version: 7.4.3
    cpe:2.3:a:sap:sap_db:7.4.3
  • Sap » Sap Db » Version: 7.4.3.7_beta
    cpe:2.3:a:sap:sap_db:7.4.3.7_beta
  • Sap » Sap Db » Version: 7.5
    cpe:2.3:a:sap:sap_db:7.5


Contact Us

Shodan ® - All rights reserved