← Vulnerability feed

Vulnerability record · CVE-2003-0945 · published 15 December 2003

CVE-2003-0945: Sap db vulnerability

Sap · Sap Db

The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.

7.5 CVSS 2.0 High EPSS 1.5% · top 27.5%
7.5CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0945 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-3614SAP DB Web Server waHTTP.exe stack buffer overflowwaHTTP.exe, the SAP DB Web Server component, contains multiple stack-based buffer overflows reachable through HTTP request fields such as a cookie va…EPSS 70%analysed7.5CVE-2003-0939Sap db vulnerabilityeo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code vi…EPSS 3.1%7.5CVE-2003-0941Sap db vulnerabilityweb-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct reque…EPSS 1.5%7.5CVE-2003-0942Sap db vulnerabilityBuffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a …EPSS 2.7%7.5CVE-2003-0943Sap db vulnerabilityweb-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially …EPSS 1.5%7.5CVE-2003-0944Sap db vulnerabilityBuffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL wit…EPSS 2.7%7.2CVE-2002-1576Sap db vulnerabilitylserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain pri…EPSS 0.90%7.2CVE-2003-1033Sap db vulnerabilityThe (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2003-0945), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.