PT-2003-1320 · Protegrity · Protegrity Secure.Data Extension Feature

Sss Sss

·

Published

2003-03-14

·

Updated

2016-10-18

·

CVE-2003-0030

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Protegrity Secure.Data Extension Feature (SEF) versions prior to 2.2.3.9
Description The issue concerns buffer overflows in the protegrity.dll component, allowing attackers with SQL access to execute arbitrary code. This can be achieved through the extended stored procedures xp pty checkusers, xp pty insert, or xp pty select.
Recommendations For versions prior to 2.2.3.9, update to version 2.2.3.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the extended stored procedures xp pty checkusers, xp pty insert, and xp pty select to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0030

Affected Products

Protegrity Secure.Data Extension Feature