Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6qc-f493-x3mg

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.

EPSS

Процентиль: 10%
0.00036
Низкий

Связанные уязвимости

nvd
почти 22 года назад

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.

EPSS

Процентиль: 10%
0.00036
Низкий