Skip to main content

Vendor/product archive

sap / maxdb CVEs

Beta · best-effort

8 CVEs tagged to sap / maxdb3 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2018-2450

Published Aug 14, 2018

SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1185

Published Mar 29, 2010

Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid length parameter in a h…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1810

Published Aug 1, 2008

Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0306

Published Mar 11, 2008

sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0307

Published Mar 11, 2008

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap cor…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0244

Published Jan 12, 2008

SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1