PT-2003-1473 · Sap · Sap Database
Larry W. Cashdollar
·
Published
2003-05-08
·
Updated
2016-10-18
·
CVE-2003-0265
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SAP database version 7.3.0.29
Description:
A race condition issue exists in SDBINST for the SAP database, where critical files are created with world-writable permissions before the setuid bits are initialized. This allows local attackers to potentially gain root privileges by modifying these files before the permissions are changed.
Recommendations:
For SAP database version 7.3.0.29, consider restricting access to the SDBINST installation process until a fix is available, and ensure that all files created during the installation have appropriate permissions set immediately to prevent unauthorized modifications.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Database