First published: Tue Dec 31 2002(Updated: )
Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =2000-sp2 | |
Microsoft SQL Server | =2000 | |
Microsoft SQL Server | =2000-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1981 is considered a high severity vulnerability due to its potential to allow unauthorized configuration changes in Microsoft SQL Server.
To fix CVE-2002-1981, it's recommended to upgrade Microsoft SQL Server to a version later than SQL Server 2000 SP2.
CVE-2002-1981 affects Microsoft SQL Server 2000 and its Service Pack 1 and Service Pack 2.
Attackers exploiting CVE-2002-1981 can execute stored procedures that modify critical server configurations, including startup and alert settings.
Yes, CVE-2002-1981 is a publicly documented vulnerability that has been acknowledged in security advisories.