CVE-2008-0306: Medium severity sap maxdb vulnerability
Published Mar 11, 2008
·Updated
sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings.
Affected Software
1 affected component
SAP MaxDB=7.6.0.37
Event History
Mar 11, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0306?
CVE-2008-0306 has a high severity rating as it allows local users to execute arbitrary commands.
2
How do I fix CVE-2008-0306?
To fix CVE-2008-0306, ensure that environment variables used by sdbstarter are properly validated and restricted.
3
Which versions of SAP MaxDB are affected by CVE-2008-0306?
CVE-2008-0306 affects SAP MaxDB version 7.6.0.37 and possibly other versions.
4
Who can exploit the vulnerability identified in CVE-2008-0306?
Local users can exploit the vulnerability identified in CVE-2008-0306.
5
What is the impact of CVE-2008-0306 on SAP MaxDB?
The impact of CVE-2008-0306 on SAP MaxDB is that it allows unauthorized command execution by local users.