Local Access Vulnerability in SAP R/3 Web Application Server Demo by SAP
CVE-2001-0366

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
27 June 2001

What is CVE-2001-0366?

A vulnerability exists in the SAP R/3 Web Application Server Demo prior to version 1.5, where the 'saposcol' component relies on the untrusted PATH environmental variable to locate and execute the expand program. This flaw enables local users to modify the PATH variable to point to a malicious version of the expand program, potentially leading to unauthorized root access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.