PT-2003-1473 · Sap · Sap Database

Larry W. Cashdollar

·

Publicado

2003-05-08

·

Atualizado

2016-10-18

·

CVE-2003-0265

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SAP database version 7.3.0.29
Description: A race condition issue exists in SDBINST for the SAP database, where critical files are created with world-writable permissions before the setuid bits are initialized. This allows local attackers to potentially gain root privileges by modifying these files before the permissions are changed.
Recommendations: For SAP database version 7.3.0.29, consider restricting access to the SDBINST installation process until a fix is available, and ensure that all files created during the installation have appropriate permissions set immediately to prevent unauthorized modifications.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0265

Produtos afetados

Sap Database