Maxdb
Vendor:
First CVE: Jan 12, 2008 · Active for 18 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Maxdb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 12, 2008
18 years ago
Most Recent CVE
Aug 14, 2018
2,901 days ago
CVE Severity & Scoring
Maxdb8 CVEs
38%
63%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (12.5%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None1 (12.5%)
Unknown7 (87.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (12.5%)
None0 (0.0%)
Unknown7 (87.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0244HIGH SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, | Jan 12, 2008 | 10.0 | 85 | NO | YES |
CVE-2010-1185HIGH Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid length parameter in a ha | Mar 29, 2010 | 10.0 | 44 | NO | YES |
CVE-2008-0307HIGH Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corr | Mar 11, 2008 | 9.3 | 30 | NO | NO |
CVE-2018-2450HIGH SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive | Aug 14, 2018 | 7.2 | 23 | NO | NO |
CVE-2015-2282HIGH Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server A | Jun 2, 2015 | 7.5 | 20 | NO | NO |
CVE-2008-0306MEDIUM sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration s | Mar 11, 2008 | 6.9 | 18 | NO | NO |
CVE-2015-2278MEDIUM The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Ser | Jun 2, 2015 | 5.0 | 15 | NO | NO |
CVE-2008-1810MEDIUM Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable. | Aug 1, 2008 | 4.4 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Maxdb
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.9 | 1 | 7.2 | 1.7% | 0 | 0 |
| 7.8 | 1 | 7.2 | 1.7% | 0 | 0 |
| 7.6.06 | 1 | 10.0 | 15.2% | 0 | 1 |
| 7.6.0.37 | 3 | 8.7 | 6.5% | 0 | 1 |
| 7.6.03.15 | 1 | 4.4 | 0.3% | 0 | 0 |
| 7.6 | 2 | 6.3 | 2.8% | 0 | 0 |
| 7.5 | 2 | 6.3 | 2.8% | 0 | 0 |
| 7.4.3.32 | 1 | 10.0 | 15.2% | 0 | 1 |