First published: Fri Nov 21 2003(Updated: )
The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP MaxDB | <=7.4.03.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0945 is considered a high severity vulnerability due to its potential for unauthorized access.
Fixing CVE-2003-0945 involves upgrading to SAP DB version 7.4.03.30 or later to eliminate predictable session IDs.
Attackers can exploit CVE-2003-0945 to perform unauthorized activities by predicting and using valid session IDs.
SAP DB versions prior to 7.4.03.30, specifically up to version 7.4.03.29, are affected by CVE-2003-0945.
There is no widely recommended workaround for CVE-2003-0945; upgrading to the patched version is advised.