2024-12-08 03:06:42 +00:00

107 lines
3.1 KiB
JSON

{
"id": "CVE-2003-0265",
"sourceIdentifier": "cve@mitre.org",
"published": "2003-05-27T04:00:00.000",
"lastModified": "2024-11-20T23:44:20.843",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed."
},
{
"lang": "es",
"value": "Condici\u00f3n de carrera (\"race condition\") en SDINST para base de datos SAP 7.3.0.29 crea ficheros cr\u00edticos con permisos de escritura para todo el mundo antes de inicializar los bits uid, lo que permite que atacantes locales obtengan privilegios modificando los ficheros antes de que los permisos sean cambiados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"baseScore": 6.2,
"accessVector": "LOCAL",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 1.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:sap_db:7.3.29:*:*:*:*:*:*:*",
"matchCriteriaId": "1E504D0B-5C30-4D39-BC8B-97966BC80E1C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:sap_db:7.4.3.7_beta:*:*:*:*:*:*:*",
"matchCriteriaId": "60910268-6E1F-4648-A20E-9C5C0DCBCF18"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=105232424810097&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/7421",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://marc.info/?l=bugtraq&m=105232424810097&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/7421",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
]
}
]
}