HIGH
The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program
Published Mar 16, 2004
7.2
HIGHCVSS 2.0
EPSS 0.35%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.