Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SAP MaxDB 'dbmsrv' Process 'PATH' Environment Variable Local Privilege Escalation Vulnerability

SAP MaxDB is prone to a local privilege-escalation vulnerability that occurs in the 'dbmsrv' process because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary code with 'sdb:sdba' privileges. Successfully exploiting this issue will compromise the affected application and possibly the underlying computer.

SAP MaxDB 7.6.03.15 on Linux is vulnerable; other versions running on different platforms may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus