HIGH
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program
Published Mar 16, 2004
7.2
HIGHCVSS 2.0
EPSS 0.90%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.