PT-2010-2895 · Sap · Sap Maxdb

Abdulaziz Hariri

·

Publicado

2010-03-16

·

Atualizado

2018-10-10

·

CVE-2010-1185

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP MaxDB versions 7.4.3.32, 7.6.0.37 through 7.6.06
Description The issue is related to a stack-based buffer overflow in the serv.exe component. It can be triggered by sending an invalid length parameter in a handshake packet to TCP port 7210, allowing remote attackers to execute arbitrary code.
Recommendations For SAP MaxDB version 7.4.3.32, update to a version that includes a fix for this issue. For SAP MaxDB versions 7.6.0.37 through 7.6.06, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to TCP port 7210 to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1185
ZDI-10-032

Produtos afetados

Sap Maxdb