>> SAP DB "waHTTP" Multiple Field Handling Remote Command Execution Vulnerability
Title : SAP DB "waHTTP" Multiple Field Handling Remote Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-2453 CVE ID : CVE-2007-3614
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-06
Technical Description
A vulnerability has been identified in SAP DB, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error in the "waHTTP.exe" service (port 9999/TCP) when processing malformed HTTP requests, which could be exploited by attackers to crash or compromise a vulnerable server via a specially crafted HTTP request.