PT-2004-1212 · Sap · Sap Db
Kf
·
Published
2004-03-16
·
Updated
2017-07-11
·
CVE-2003-1034
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP DB versions 7.x
Description
The RPM installation of SAP DB creates certain programs with world-writable permissions, allowing local users to gain privileges by modifying those programs. Specifically, the programs
dbmsrv or lserver are created with these permissions.Recommendations
For SAP DB version 7.x, change the permissions of the
dbmsrv and lserver programs to prevent world-writable access. As a temporary workaround, consider restricting access to these programs until a proper fix is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Db