CVE-2003-1033
The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- sap/sap db
- Source
- cve@mitre.org
References
- http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html
- http://marc.info/?l=bugtraq&m=105103613727471&w=2
- http://www.securityfocus.com/bid/7407Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7408
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11842
- http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html
- http://marc.info/?l=bugtraq&m=105103613727471&w=2
- http://www.securityfocus.com/bid/7407Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7408
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11842
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.