VDB
CVE-2007-3614
CVE-2007-3614
PUBLISHED
CVSS 7.5 HIGH
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
EPSS 82.93% · 99.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
82.93%
99.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sap | sap_db | 7.3.00, 7.3.29, 7.4 |
| n/a | n/a | * |
Timeline
- Jul 6, 2007 CVE Published
- Jul 16, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 27, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://www.ngssoftware.com/advisories/critical-risk-vulnerability-in-sap-db-web-server-stack-overflow/ url
- 1018341 vdb
- sapdb-wahttp-bo(35277) vdb
- 24773 vdb
- 37838 vdb
- 20070705 SAP DB Web Server Stack Overflow mailing-list
- 2867 third-party-advisory
- VU#679041 third-party-advisory
- ADV-2007-2453 vdb
- 25954 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-3614 advisory
- http://www.ngssoftware.com/advisories/critical-risk-vulnerability-in-sap-db-web-server-stack-overflow url