Code Injection Vulnerability in SAP MaxDB ODBC Driver
CVE-2018-2418
5.5MEDIUM
Summary
The SAP MaxDB ODBC driver is susceptible to a code injection vulnerability that affects all versions prior to 7.9.09.07. An attacker can exploit this flaw to inject malicious code that the application will execute, potentially allowing unauthorized access and control over application behavior. Users should seek the latest security updates to mitigate this risk.
Affected Version(s)
SAP MaxDB ODBC driver all versions before 7.9.09.07
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved