Home    |    View Topics    |    Search    |    Contact Us    |   



Category:   Application (Database)  >   MaxDB Vendors:   SAP
MaxDB 'sdbstarter' Utility Lets Local Users Gain Root Privileges
SecurityTracker Alert ID:  1019570
SecurityTracker URL:
CVE Reference:   CVE-2008-0306   (Links to External Site)
Date:  Mar 11 2008
Impact:   Execution of arbitrary code via local system, Root access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s):; possibly other versions
Description:   A vulnerability was reported in MaxDB in the 'sdbstarter' application. A local user can obtain root privileges on the target system.

A local user in the 'sdba' user group can set a specially crafted environment variable to execute arbitrary commands on the target system with root privileges.

The vendor was notified on December 5, 2007.

Joshua J. Drake of VeriSign iDefense Labs reported this vulnerability.

Impact:   A local user in the 'sdba' user group can obtain root privileges on the target system.
Solution:   The vendor has issued a fix (see SAP note 1140135).
Vendor URL: (Links to External Site)
Cause:   Not specified
Underlying OS:  Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), UNIX (Tru64)

Message History:   None.

 Source Message Contents

Subject:  iDefense Security Advisory 03.10.08: SAP MaxDB sdbstarter Privilege

iDefense Security Advisory 03.10.08
Mar 10, 2008


SAP's MaxDB is a database software product. MaxDB was released as open
source from version 7.5 up to version 7.6.00. Later versions are no
longer open source but are available for download from the SAP SDN
website ( as a community edition with free community
support for public use beyond the scope of SAP applications. The
"sdbstarter" program is set-uid root and installed by default. For more
information, visit the product's website at the following URL.


Local exploitation of a design error in the "sdbstarter" program, as
distributed with SAP AG's MaxDB, could allow attackers to elevate
privileges to root.

This vulnerability exists due to a design error in the handling of
certain environment variables. These variables are used to specify the
configuration settings to be used by various MaxDB components. Since
the "sdbstarter" program honors these settings, an attacker can execute
arbitrary code with root privileges.


Exploitation allows an attacker to execute arbitrary code with root
privileges. To exploit this vulnerability, an attacker must be able to
execute the "sdbstarter" program. In a default installation, this
requires that the attacker be a member of the "sdba" group.

It is important to note that this vulnerability is not architecture
dependent. This vulnerability is trivially exploitable on any
Unix-based SAP MaxDB installation.


iDefense has confirmed the existence of this vulnerability in SAP AG's
MaxDB version on both Linux and Solaris. Other versions for
Unix-like systems are suspected to be vulnerable. Windows releases do
not include the "sdbstarter" program.


iDefense is currently unaware of any effective workaround for this


SAP AG has addressed this vulnerability by releasing a new version of
MaxDB. For more information, consult SAP note 1140135.


The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2008-0306 to this issue. This is a candidate for inclusion in
the CVE list (, which standardizes names for
security problems.


12/05/2007  Initial vendor notification
12/06/2007  Initial vendor response
03/10/2008  Coordinated public disclosure


This vulnerability was discovered by Joshua J. Drake of VeriSign
iDefense Labs.

Get paid for vulnerability research

Free tools, research and upcoming events


Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDefense. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically,
please e-mail for permission.

Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition.
 There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct,
indirect, or consequential loss or damage arising from use of, or
reliance on, this information.
To unsubscribe, go here:


Go to the Top of This SecurityTracker Archive Page

Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, LLC