CVE-2003-1033
N/A
N/A
Summary
The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11842
- http://www.securityfocus.com/bid/7407
- http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html
- http://www.securityfocus.com/bid/7408
- http://marc.info/?l=bugtraq&m=105103613727471&w=2
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11842
- http://www.securityfocus.com/bid/7407
- http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html
- http://www.securityfocus.com/bid/7408
- http://marc.info/?l=bugtraq&m=105103613727471&w=2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.