SAP MaxDB Unspecified Remote Execution Vulnerability
BID:26822
Info
SAP MaxDB Unspecified Remote Execution Vulnerability
| Bugtraq ID: | 26822 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2007 12:00AM |
| Updated: | Dec 12 2007 09:32PM |
| Credit: | WabiSabiLabi disclosed this vulnerability. |
| Vulnerable: |
SAP MaxDB 7.6.00.37 SAP MaxDB 7.4.3.32 |
| Not Vulnerable: | |
Discussion
SAP MaxDB Unspecified Remote Execution Vulnerability
SAP MaxDB is prone to an unspecified remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will crash the application.
This issue affects MaxDB 7.6.00.37 and 7.4.3.32; other versions may also be affected.
SAP MaxDB is prone to an unspecified remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will crash the application.
This issue affects MaxDB 7.6.00.37 and 7.4.3.32; other versions may also be affected.
Exploit / POC
SAP MaxDB Unspecified Remote Execution Vulnerability
A proof of concept has been developed. It may be publicly available or circulating in the wild, but this has not been confirmed.
A proof of concept has been developed. It may be publicly available or circulating in the wild, but this has not been confirmed.
Solution / Fix
SAP MaxDB Unspecified Remote Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SAP MaxDB Unspecified Remote Execution Vulnerability
References:
References:
- Focus on: SAP MaxDB remote code execution (WabiSabiLabi)
- SAP MaxDB Homepage (SAP)
- ZD-00000166: SAP MaxDB suffers local vulnerability. (WabiSabiLabi )