CVE-2003-0940

4 documents4 sources
Severity
5.0MEDIUM
EPSS
0.9%
top 24.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15
Latest updateApr 29

Description

Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDsap/sap_db7.4.03.29

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vhjj-wvp5-r932: Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 72022-04-29
CVEList
CVE-2003-0940: Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 72003-11-21

💬Community

1
Bugzilla
CVE-2003-0542 multiple flaws in Apache (CVE-2003-0542, CVE-2003-0987, CVE-2004-0940)2005-10-25