PT-2018-15572 · Sap · Sap Maxdb

Published

2018-08-14

·

Updated

2018-10-11

·

CVE-2018-2450

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP MaxDB (liveCache) versions 7.8 and 7.9
Description The issue allows an attacker with DBM operator privileges to execute crafted database queries, potentially reading, modifying, or deleting sensitive data from the database.
Recommendations For SAP MaxDB (liveCache) version 7.8, update to a version that includes a fix for this issue. For SAP MaxDB (liveCache) version 7.9, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting DBM operator privileges to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-2450

Affected Products

Sap Maxdb