CVE-2003-0938

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/12/2003
Last modified:
03/04/2025

Description

vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:sap_db:*:*:*:*:*:*:*:* 7.4.03.27 (including)