First published: Fri Nov 21 2003(Updated: )
web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redirect attacks against internal databases via (1) waecho, (2) Web SQL Interface (websql), or (3) Web Database Manager (webdbm).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Sap Db | <=7.4.03.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0943 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2003-0943, users should upgrade SAP DB to version 7.4.03.30 or later, which disables default services.
CVE-2003-0943 affects the waecho, Web SQL Interface (websql), and Web Database Manager (webdb) services.
Organizations using SAP DB versions prior to 7.4.03.30 are at risk of CVE-2003-0943.
Yes, CVE-2003-0943 can be exploited remotely, allowing attackers to access internal databases.