CVE-2007-3614
Sap DB - Buffer Overflow
Title source: ruleDescription
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16758
exploitdb
WORKING POC
VERIFIED
by Heretic2 · c++remotewindows
https://www.exploit-db.com/exploits/4157
exploitdb
WORKING POC
VERIFIED
by Mark Litchfield · cremotewindows
https://www.exploit-db.com/exploits/30278
metasploit
WORKING POC
GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sapdb_webtools.rb
References (10)
Scores
EPSS
0.8410
EPSS Percentile
99.3%
Details
Status
published
Products (8)
sap/sap_db
7.3.00
sap/sap_db
7.3.29
sap/sap_db
7.4
sap/sap_db
7.4.3
sap/sap_db
7.4.3.7_beta
sap/sap_db
7.4.03.29
sap/sap_db
7.4.03.30
sap/sap_db
7.5
Published
Jul 06, 2007
Tracked Since
Feb 18, 2026