CVE-2002-1578
Last modified
CVE-2002-1578 is a vulnerability of currently unknown severity. The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not password-protected.. EPSS estimates a 2.66% chance of exploitation in the next 30 days.
Description
The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not password-protected.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap R 3 | All versions |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0387.htmlExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4613Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0387.htmlExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4613Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-1578?
How severe is CVE-2002-1578?
How do I fix CVE-2002-1578?
Are you affected by CVE-2002-1578?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
