Lucene search

K
cveMitreCVE-2008-0244
HistoryJan 12, 2008 - 2:46 a.m.

CVE-2008-0244

2008-01-1202:46:00
CWE-20
mitre
web.nvd.nist.gov
31
2
sap
maxdb
remote command execution
cve-2008-0244
security vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.968

Percentile

99.7%

SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via “&&” and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.

Affected configurations

Nvd
Node
sapmaxdbRange7.6.3_build_007
VendorProductVersionCPE
sapmaxdb*cpe:2.3:a:sap:maxdb:*:*:*:*:*:*:*:*

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.968

Percentile

99.7%