Vulnerability record · CVE-2006-4305 · published 30 August 2006
CVE-2006-4305: SAP DB and MaxDB buffer overflow via long database name in WebDBM client
Mysql · Maxdb
SAP DB and MaxDB before 7.6.00.30 contain a buffer overflow that is triggered when a remote attacker supplies an overly long database name while connecting through a WebDBM client. Because the overflow is remotely reachable and can lead to arbitrary code execution, it is a serious pre-authentication risk for exposed database services.
Description
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe vulnerability is remotely exploitable without authentication and yields complete compromise of the database host, with a CVSS 2.0 score of 10 and very high EPSS probability.
What it is
SAP DB and MaxDB before 7.6.00.30 contain a buffer overflow that is triggered when a remote attacker supplies an overly long database name while connecting through a WebDBM client. Because the overflow is remotely reachable and can lead to arbitrary code execution, it is a serious pre-authentication risk for exposed database services.
Impact
A remote attacker can execute arbitrary code in the context of the affected database service, potentially gaining full control of the host. The CVSS 2.0 vector indicates complete loss of confidentiality, integrity and availability.
Attack surface
The flaw is reached over the network through the WebDBM client connection path by sending a crafted long database name. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.713 (99.38th percentile), and multiple references carry Patch and Vendor Advisory tags, indicating public technical detail and available fixes.
What to do
- Upgrade SAP DB and MaxDB to version 7.6.00.30 or later, or apply the vendor patch referenced in the advisories.
- Apply the Debian DSA-1190 update if running the Debian-packaged version.
- Restrict network access to WebDBM and database listener ports to trusted hosts only.
- Disable or block the WebDBM client interface where it is not operationally required.
- Monitor vendor advisories for any further updates to the affected components.
Detection
- Inspect WebDBM and database service logs for connection attempts containing unusually long or malformed database name parameters.
- Monitor for crashes or abnormal process termination of SAP DB/MaxDB services that could indicate overflow attempts.
- Use network monitoring to alert on oversized database name fields in WebDBM connection traffic.
- Watch for unexpected child processes or outbound connections spawned by the database service after connection handling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-4305 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-4305), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.