First published: Tue Mar 16 2004(Updated: )
The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP MaxDB | =7.3.00 | |
SAP MaxDB | =7.4 | |
SAP MaxDB | =7.3.00 | |
SAP MaxDB | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1034 is considered a high severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2003-1034, change the permissions of the dbmsrv and lserver programs to restrict write access to only authorized users.
CVE-2003-1034 affects SAP DB versions 7.3.00 and 7.4.
The vulnerable programs in CVE-2003-1034 are dbmsrv and lserver.
Yes, local users can exploit CVE-2003-1034 to gain elevated privileges by modifying the vulnerable programs.