CVE-2007-3614

Sap DB - Buffer Overflow

Title source: rule

Description

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16758
exploitdb WORKING POC VERIFIED
by Heretic2 · c++remotewindows
https://www.exploit-db.com/exploits/4157
exploitdb WORKING POC VERIFIED
by Mark Litchfield · cremotewindows
https://www.exploit-db.com/exploits/30278
metasploit WORKING POC GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sapdb_webtools.rb

Scores

EPSS 0.8410
EPSS Percentile 99.3%

Details

Status published
Products (8)
sap/sap_db 7.3.00
sap/sap_db 7.3.29
sap/sap_db 7.4
sap/sap_db 7.4.3
sap/sap_db 7.4.3.7_beta
sap/sap_db 7.4.03.29
sap/sap_db 7.4.03.30
sap/sap_db 7.5
Published Jul 06, 2007
Tracked Since Feb 18, 2026