7.5

CVE-2007-3614

Exploit

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPSap Db Version7.3.00
SAPSap Db Version7.3.29
SAPSap Db Version7.4
SAPSap Db Version7.4.3
SAPSap Db Version7.4.3.7_beta
SAPSap Db Version7.4.03.29
SAPSap Db Version7.4.03.30
SAPSap Db Version7.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 77.71% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P