Code Injection Vulnerability in SAP MaxDB ODBC Driver
CVE-2018-2418

5.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 May 2018

Summary

The SAP MaxDB ODBC driver is susceptible to a code injection vulnerability that affects all versions prior to 7.9.09.07. An attacker can exploit this flaw to inject malicious code that the application will execute, potentially allowing unauthorized access and control over application behavior. Users should seek the latest security updates to mitigate this risk.

Affected Version(s)

SAP MaxDB ODBC driver all versions before 7.9.09.07

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.