CVE-2008-0244: Input Validation
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in execsdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0244?
CVE-2008-0244 is considered a critical vulnerability as it allows remote attackers to execute arbitrary commands on vulnerable systems.
How do I fix CVE-2008-0244?
To fix CVE-2008-0244, upgrade SAP MaxDB to version 7.6.03 build 008 or later.
Which versions of SAP MaxDB are affected by CVE-2008-0244?
CVE-2008-0244 affects SAP MaxDB versions 7.6.03 build 007 and earlier.
What are the potential risks associated with CVE-2008-0244?
The risks associated with CVE-2008-0244 include unauthorized remote code execution, data loss, and system compromise.
What is the attack vector for CVE-2008-0244?
The attack vector for CVE-2008-0244 involves sending specially crafted input containing shell metacharacters to execute commands.