CVE-2008-0307: Critical severity sap maxdb vulnerability
Published Mar 11, 2008
·Updated
Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.
Affected Software
1 affected component
SAP MaxDB=7.6.0.37
Event History
Mar 11, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0307?
CVE-2008-0307 is classified as a critical vulnerability allowing remote code execution.
2
How do I fix CVE-2008-0307?
To fix CVE-2008-0307, upgrade SAP MaxDB to version 7.6.0.38 or later.
3
What causes the vulnerability CVE-2008-0307?
CVE-2008-0307 is caused by an integer signedness error that leads to heap corruption.
4
Who is affected by CVE-2008-0307?
CVE-2008-0307 affects users of SAP MaxDB version 7.6.0.37 and possibly earlier versions.
5
Can CVE-2008-0307 be exploited remotely?
Yes, CVE-2008-0307 can be exploited by remote attackers to execute arbitrary code.