Privilege Escalation via User-Provided INSTROOT Path in SAP DB Development Tools 7.x

Privilege Escalation via User-Provided INSTROOT Path in SAP DB Development Tools 7.x

CVE-2003-1033 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.

Learn more about our Cis Benchmark Audit For Server Software.