Local Access Vulnerability in SAP R/3 Web Application Server Demo by SAP
CVE-2001-0366
Currently unrated
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 27 June 2001
What is CVE-2001-0366?
A vulnerability exists in the SAP R/3 Web Application Server Demo prior to version 1.5, where the 'saposcol' component relies on the untrusted PATH environmental variable to locate and execute the expand program. This flaw enables local users to modify the PATH variable to point to a malicious version of the expand program, potentially leading to unauthorized root access.
References
Timeline
Vulnerability published
Vulnerability Reserved