SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
BID:38769
Info
SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
| Bugtraq ID: | 38769 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1185 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2010 12:00AM |
| Updated: | May 10 2010 12:32PM |
| Credit: | AbdulAziz Hariri of Insight Technologies |
| Vulnerable: |
SAP MaxDB 7.6.6 SAP MaxDB 7.6.3 build 007 SAP MaxDB 7.6.03.15 SAP MaxDB 7.6.00.37 SAP MaxDB 7.6.0.37 SAP MaxDB 7.4.3.32 |
| Not Vulnerable: | |
Discussion
SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
SAP MaxDB is prone to an unspecified remote code-execution vulnerability because it fails to sufficiently validate user-supplied input.
An attacker can leverage this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
SAP MaxDB is prone to an unspecified remote code-execution vulnerability because it fails to sufficiently validate user-supplied input.
An attacker can leverage this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
An exploit is available:
An exploit is available:
Solution / Fix
SAP MaxDB 'serv.exe' Unspecified Remote Code Execution Vulnerability
Solution:
Vendor updates are available through SAP note 1409425; please contact the vendor for more information.
Solution:
Vendor updates are available through SAP note 1409425; please contact the vendor for more information.