PT-2008-1946 · Sap · Sap Maxdb
Published
2008-03-11
·
Updated
2017-08-08
·
CVE-2008-0306
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP MaxDB version 7.6.0.37
Description
The issue allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings.
Recommendations
For SAP MaxDB version 7.6.0.37, consider restricting access to environment variables that can modify configuration settings until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Maxdb