7.5

CVE-2007-3614

Exploit

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

Data is provided by the National Vulnerability Database (NVD)
SAPSap Db Version7.3.00
SAPSap Db Version7.3.29
SAPSap Db Version7.4
SAPSap Db Version7.4.3
SAPSap Db Version7.4.3.7_beta
SAPSap Db Version7.4.03.29
SAPSap Db Version7.4.03.30
SAPSap Db Version7.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 77.71% 0.989
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P