CVE-2002-1576: High severity SAP SAP DB vulnerability
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability associated with CVE-2002-1576?
CVE-2002-1576 allows local users to gain elevated privileges by exploiting the lserver program in SAP DB 7.3 through a malicious lserversrv program.
What versions of SAP DB are affected by CVE-2002-1576?
CVE-2002-1576 affects SAP DB versions 7.3 and earlier.
How can I mitigate the risk of CVE-2002-1576?
To mitigate CVE-2002-1576, ensure that users do not have the ability to create symlinks in directories containing the lserver program.
What are the potential impacts of exploiting CVE-2002-1576?
Exploiting CVE-2002-1576 can lead to unauthorized privilege escalation for local users.
Is there a patch available for CVE-2002-1576?
There is no specific patch for CVE-2002-1576, but upgrading to a later version of SAP DB can help prevent this vulnerability.