CVE-2003-1034: Medium severity sap sap db vulnerability
Published Mar 16, 2004
·Updated
The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.
Affected Software
4 affected components
SAP SAP DB=7.3.00
SAP SAP DB=7.4
SAP SAP DB=7.3.00
SAP SAP DB=7.4
Remediation
Patch Available
Event History
Mar 16, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1034?
CVE-2003-1034 is considered a high severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2003-1034?
To fix CVE-2003-1034, change the permissions of the dbmsrv and lserver programs to restrict write access to only authorized users.
3
Which versions are affected by CVE-2003-1034?
CVE-2003-1034 affects SAP DB versions 7.3.00 and 7.4.
4
What programs are vulnerable in CVE-2003-1034?
The vulnerable programs in CVE-2003-1034 are dbmsrv and lserver.
5
Can local users exploit CVE-2003-1034?
Yes, local users can exploit CVE-2003-1034 to gain elevated privileges by modifying the vulnerable programs.