Unrated severityNVD Advisory· Published Jul 6, 2007· Updated Apr 23, 2026
CVE-2007-3614
CVE-2007-3614
Description
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
Affected products
8cpe:2.3:a:sap:sap_db:7.3.00:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:sap:sap_db:7.3.00:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.3.29:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.4:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.4.03.29:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.4.03.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.4.3.7_beta:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_db:7.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.securityfocus.com/bid/24773nvdExploitPatch
- www.kb.cert.org/vuls/id/679041nvdUS Government Resource
- osvdb.org/37838nvd
- secunia.com/advisories/25954nvd
- securityreason.com/securityalert/2867nvd
- www.ngssoftware.com/advisories/critical-risk-vulnerability-in-sap-db-web-server-stack-overflow/nvd
- www.securityfocus.com/archive/1/472891/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/2453nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35277nvd
News mentions
0No linked articles in our index yet.