PT-2004-1128 · Sap · Sap Db
Publicado
2004-03-16
·
Atualizado
2017-07-11
·
CVE-2002-1576
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP DB versions 7.3 and earlier
Description
The issue concerns the lserver in SAP DB, where it uses the current working directory to find and execute the lserversrv program. This allows local users to gain privileges by using a malicious lserversrv program that is called from a directory with a symlink to the lserver program.
Recommendations
For SAP DB versions 7.3 and earlier, consider restricting access to the lserver program to minimize the risk of exploitation. As a temporary workaround, avoid using symlinks in directories from which the lserver program is executed until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sap Db