PT-2018-15572 · Sap · Sap Maxdb
Published
2018-08-14
·
Updated
2018-10-11
·
CVE-2018-2450
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP MaxDB (liveCache) versions 7.8 and 7.9
Description
The issue allows an attacker with DBM operator privileges to execute crafted database queries, potentially reading, modifying, or deleting sensitive data from the database.
Recommendations
For SAP MaxDB (liveCache) version 7.8, update to a version that includes a fix for this issue.
For SAP MaxDB (liveCache) version 7.9, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting DBM operator privileges to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Maxdb