← Vulnerability feed

Vulnerability record · CVE-2006-4305 · published 30 August 2006

CVE-2006-4305: SAP DB and MaxDB buffer overflow via long database name in WebDBM client

Mysql · Maxdb

SAP DB and MaxDB before 7.6.00.30 contain a buffer overflow that is triggered when a remote attacker supplies an overly long database name while connecting through a WebDBM client. Because the overflow is remotely reachable and can lead to arbitrary code execution, it is a serious pre-authentication risk for exposed database services.

10.0 CVSS 2.0 High EPSS 71% · top 0.6%
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityThe vulnerability is remotely exploitable without authentication and yields complete compromise of the database host, with a CVSS 2.0 score of 10 and very high EPSS probability.

What it is

SAP DB and MaxDB before 7.6.00.30 contain a buffer overflow that is triggered when a remote attacker supplies an overly long database name while connecting through a WebDBM client. Because the overflow is remotely reachable and can lead to arbitrary code execution, it is a serious pre-authentication risk for exposed database services.

Impact

A remote attacker can execute arbitrary code in the context of the affected database service, potentially gaining full control of the host. The CVSS 2.0 vector indicates complete loss of confidentiality, integrity and availability.

Attack surface

The flaw is reached over the network through the WebDBM client connection path by sending a crafted long database name. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.713 (99.38th percentile), and multiple references carry Patch and Vendor Advisory tags, indicating public technical detail and available fixes.

What to do

  • Upgrade SAP DB and MaxDB to version 7.6.00.30 or later, or apply the vendor patch referenced in the advisories.
  • Apply the Debian DSA-1190 update if running the Debian-packaged version.
  • Restrict network access to WebDBM and database listener ports to trusted hosts only.
  • Disable or block the WebDBM client interface where it is not operationally required.
  • Monitor vendor advisories for any further updates to the affected components.

Detection

  • Inspect WebDBM and database service logs for connection attempts containing unusually long or malformed database name parameters.
  • Monitor for crashes or abnormal process termination of SAP DB/MaxDB services that could indicate overflow attempts.
  • Use network monitoring to alert on oversized database name fields in WebDBM connection traffic.
  • Watch for unexpected child processes or outbound connections spawned by the database service after connection handling.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4305 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-1274Mysql maxdb vulnerabilityStack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execut…EPSS 4.2%10.0CVE-2005-0684MySQL MaxDB web tool buffer overflows allow remote code executionThe MySQL MaxDB web tool before 7.5.00.26 contains multiple buffer overflows, one reachable through an HTTP GET request with a long file parameter af…EPSS 69%analysed10.0CVE-2004-1168Mysql maxdb vulnerabilityStack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a lon…EPSS 4.6%7.5CVE-2005-0111Mysql maxdb vulnerabilityStack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password par…EPSS 3.8%5.0CVE-2005-0083Mysql maxdb vulnerabilityMySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application …EPSS 1.4%5.0CVE-2005-0081Mysql maxdb vulnerabilityMySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invali…EPSS 1.5%5.0CVE-2005-0082Mysql maxdb vulnerabilityThe sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (cr…EPSS 1.4%5.0CVE-2004-1169Mysql maxdb vulnerabilityMaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2006-4305), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.