vendor:
SAP MaxDB
by:
S2 Crew
7.5
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: SAP MaxDB
Affected Version From: 7.7.06.09
Affected Version To: 7.7.06.09
Patch Exists: NO
Related CWE: ZDI-10-032
CPE: sap:maxdb:7.7.06.09
Platforms Tested: Windows XP SP2
2010
SAP MaxDB Malformed Handshake Request Remote Code Execution
This exploit allows an attacker to execute arbitrary code on a vulnerable SAP MaxDB server by sending a specially crafted handshake request. The vulnerability is caused by a buffer overflow in the server's handling of handshake requests, allowing an attacker to overwrite the return address and execute arbitrary code.
Mitigation:
Apply the latest patches and updates from SAP to fix this vulnerability.