CVE-2001-0366
Last modified
CVE-2001-0366 is a vulnerability of currently unknown severity. saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap R 3 Web Application Server Demo | <= 1.5 |
| Sap | Saposcol | 1.0 |
| Sap | Saposcol | 1.1 |
| Sap | Saposcol | 1.2 |
| Sap | Saposcol | 1.3 |
References
- http://www.securityfocus.com/archive/1/180498Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2662Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/180498Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2662Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0366?
How severe is CVE-2001-0366?
How do I fix CVE-2001-0366?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0358Buffer overflows in Sierra Half-Life build 1573 and earlier …
- CVE-2001-0359Format string vulnerability in Sierra Half-Life build 1573 a…
- CVE-2001-0360Directory traversal vulnerability in help.cgi in Ikonboard 2…
- CVE-2001-0361Implementations of SSH version 1.5, including (1) OpenSSH up…
- CVE-2001-0364SSH Communications Security sshd 2.4 for Windows allows remo…
- CVE-2001-0365Eudora before 5.1 allows a remote attacker to execute arbitr…
- CVE-2001-0367Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a …
- CVE-2001-0368Directory traversal vulnerability in BearShare 2.2.2 and ear…
- CVE-2001-0369Buffer overflow in lpsched on DGUX version R4.20MU06 and MU0…
- CVE-2001-0370fcheck prior to 2.57.59 calls the file signature checking pr…
- CVE-2001-0371Race condition in the UFS and EXT2FS file systems in FreeBSD…
- CVE-2001-0372Akopia Interchange 4.5.3 through 4.6.3 installs demo stores …
Are you affected by CVE-2001-0366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
