Short Name |
DB:MYSQL:MAXDB-SERVER-OF |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
DB |
Keywords |
MaxDB WebDBM Server Buffer Overflow |
Release Date |
2006/10/09 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against MaxDB Web packages. A successful attack can allow an attacker to execute arbitrary code with elevated privileges.
SAP-DB and MaxDB are prone to a remote buffer-overflow vulnerability because these applications fail to perform sufficient bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue may allow remote attackers to execute arbitrary machine code with privileges of the 'wahttp' process. Failed exploit attempts will likely crash the application, denying further service to legitimate users.