Vulnerabilities
Vulnerable Software
Sap:  >> Sap Db  >> 7.4.3.7_beta  Security Vulnerabilities
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
CVSS Score
7.5
EPSS Score
0.777
Published
2007-07-06
Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.
CVSS Score
6.2
EPSS Score
0.002
Published
2003-05-27


Contact Us

Shodan ® - All rights reserved