VDB

CVE-2007-3614

CVE-2007-3614 PUBLISHED CVSS 7.5 HIGH

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

EPSS 82.93% · 99.3th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
82.93%
99.3th percentile

Affected Products

VendorProductVersions
sapsap_db7.3.00, 7.3.29, 7.4
n/an/a*

Timeline

  • Jul 6, 2007 CVE Published
  • Jul 16, 2010 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 27, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›