Home/Product/sap db
Product

sap db

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2007-3614
all versions
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote
CVE-2006-4305
all versions
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name wh
CVE-2003-1033
all versions
The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment varia
CVE-2002-1576
all versions
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows loca
CVE-2003-0945
<= 7.4.03.29
The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers
CVE-2003-0944
<= 7.4.03.29
Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary
CVE-2003-0943
<= 7.4.03.29
web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to
CVE-2003-0942
<= 7.4.03.29
Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute ar
CVE-2003-0941
<= 7.4.03.29
web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration
CVE-2003-0940
<= 7.4.03.29
Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary
CVE-2003-0939
<= 7.4.03.27
eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execut
CVE-2003-0938
<= 7.4.03.27
vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAP
CVE-2003-0265
all versions
Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the
threatengine.sh