PT-2004-1211 · Sap · Sap Db Development Tools

Kf

·

Published

2004-03-16

·

Updated

2017-07-11

·

CVE-2003-1033

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP DB Development Tools versions 7.x
Description The issue concerns the instdbmsrv and instlserver programs in SAP DB Development Tools, which trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program. This allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.
Recommendations For SAP DB Development Tools versions 7.x, consider restricting access to the INSTROOT environment variable to prevent malicious modifications. As a temporary workaround, restrict the execution of the lserver program to trusted users only until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1033

Affected Products

Sap Db Development Tools