CVE-2003-0938

3 documents3 sources
Severity
7.2HIGH
EPSS
0.0%
top 85.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15
Latest updateApr 29

Description

vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDsap/sap_db7.4.03.27

Patches

🔴Vulnerability Details

2
GHSA
GHSA-59g6-5v86-2944: vos24u2022-04-29
CVEList
CVE-2003-0938: vos24u2003-11-21