First published: Tue Mar 11 2008(Updated: )
sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP MaxDB | =7.6.0.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0306 has a high severity rating as it allows local users to execute arbitrary commands.
To fix CVE-2008-0306, ensure that environment variables used by sdbstarter are properly validated and restricted.
CVE-2008-0306 affects SAP MaxDB version 7.6.0.37 and possibly other versions.
Local users can exploit the vulnerability identified in CVE-2008-0306.
The impact of CVE-2008-0306 on SAP MaxDB is that it allows unauthorized command execution by local users.