SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability
BID:28185
Info
SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability
| Bugtraq ID: | 28185 |
| Class: | Design Error |
| CVE: |
CVE-2008-0306 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Mar 12 2008 06:01PM |
| Credit: | Joshua J. Drake of VeriSign iDefense Labs is credited with discovering this issue. |
| Vulnerable: |
SAP MaxDB 7.6.0.37 |
| Not Vulnerable: | |
Discussion
SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability
SAP MaxDB is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code with superuser privileges. This will lead to the complete compromise of an affected computer.
This issue affects MaxDB 7.6.0.37 on both Linux and Solaris platforms. Other UNIX variants are most likely affected. Microsoft Windows versions are not vulnerable to this issue.
SAP MaxDB is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code with superuser privileges. This will lead to the complete compromise of an affected computer.
This issue affects MaxDB 7.6.0.37 on both Linux and Solaris platforms. Other UNIX variants are most likely affected. Microsoft Windows versions are not vulnerable to this issue.
Exploit / POC
SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability
An attacker can exploit this issue by gaining local interactive access to the affected computer.
An attacker can exploit this issue by gaining local interactive access to the affected computer.
Solution / Fix
SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability
Solution:
The vendor has released a new version of the application to address this issue. Please refer to SAP note 1140135 for more information.
Solution:
The vendor has released a new version of the application to address this issue. Please refer to SAP note 1140135 for more information.
References
SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability
References:
References: