ID

VAR-200712-0506


TITLE

SAP MaxDB Unspecified Remote Execution Vulnerability

Trust: 0.3

sources: BID: 26822

DESCRIPTION

SAP MaxDB is prone to an unspecified remote code-execution vulnerability. An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will crash the application. This issue affects MaxDB 7.6.00.37 and 7.4.3.32; other versions may also be affected.

Trust: 0.3

sources: BID: 26822

AFFECTED PRODUCTS

vendor:sapmodel:maxdbscope:eqversion:7.6.00.37

Trust: 0.3

vendor:sapmodel:maxdbscope:eqversion:7.4.3.32

Trust: 0.3

sources: BID: 26822

THREAT TYPE

network

Trust: 0.3

sources: BID: 26822

TYPE

Unknown

Trust: 0.3

sources: BID: 26822

EXTERNAL IDS

db:BIDid:26822

Trust: 0.3

sources: BID: 26822

REFERENCES

url:http://wabisabilabi.blogspot.com/2007/12/focus-on-sap-maxdb-remote-code.html

Trust: 0.3

url:https://www.sdn.sap.com/irj/sdn/maxdb

Trust: 0.3

url:http://wslabi.com/wabisabilabi/showbidinfo.do?code=zd-00000166

Trust: 0.3

sources: BID: 26822

CREDITS

WabiSabiLabi disclosed this vulnerability.

Trust: 0.3

sources: BID: 26822

SOURCES

db:BIDid:26822

LAST UPDATE DATE

2022-05-17T01:49:24.936000+00:00


SOURCES UPDATE DATE

db:BIDid:26822date:2007-12-12T21:32:00

SOURCES RELEASE DATE

db:BIDid:26822date:2007-12-11T00:00:00