PT-2004-1128 · Sap · Sap Db

Publicado

2004-03-16

·

Atualizado

2017-07-11

·

CVE-2002-1576

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP DB versions 7.3 and earlier
Description The issue concerns the lserver in SAP DB, where it uses the current working directory to find and execute the lserversrv program. This allows local users to gain privileges by using a malicious lserversrv program that is called from a directory with a symlink to the lserver program.
Recommendations For SAP DB versions 7.3 and earlier, consider restricting access to the lserver program to minimize the risk of exploitation. As a temporary workaround, avoid using symlinks in directories from which the lserver program is executed until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1576

Produtos afetados

Sap Db