CVE-2003-0945: High severity sap sap db vulnerability
Published Nov 21, 2003
·Updated
The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.
Affected Software
1 affected component
SAP SAP DB<=7.4.03.29
Event History
Nov 21, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 15, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0945?
CVE-2003-0945 is considered a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2003-0945?
Fixing CVE-2003-0945 involves upgrading to SAP DB version 7.4.03.30 or later to eliminate predictable session IDs.
3
What kind of attacks can be executed through CVE-2003-0945?
Attackers can exploit CVE-2003-0945 to perform unauthorized activities by predicting and using valid session IDs.
4
Which software versions are affected by CVE-2003-0945?
SAP DB versions prior to 7.4.03.30, specifically up to version 7.4.03.29, are affected by CVE-2003-0945.
5
Is there a known workaround for CVE-2003-0945?
There is no widely recommended workaround for CVE-2003-0945; upgrading to the patched version is advised.