Vulnerability record · CVE-2007-3614 · published 6 July 2007
CVE-2007-3614: SAP DB Web Server waHTTP.exe stack buffer overflow
Sap · Sap Db
waHTTP.exe, the SAP DB Web Server component, contains multiple stack-based buffer overflows reachable through HTTP request fields such as a cookie value and an additional parameter tied to sapdbwa_GetQueryString, plus other unspecified fields. Successful exploitation allows remote code execution on the database web server, which is a serious exposure for any internet- or network-reachable SAP DB deployment.
Description
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a very high EPSS score and public exploit references, though no confirmed active exploitation in KEV.
What it is
waHTTP.exe, the SAP DB Web Server component, contains multiple stack-based buffer overflows reachable through HTTP request fields such as a cookie value and an additional parameter tied to sapdbwa_GetQueryString, plus other unspecified fields. Successful exploitation allows remote code execution on the database web server, which is a serious exposure for any internet- or network-reachable SAP DB deployment.
Impact
A remote attacker can execute arbitrary code with the privileges of the waHTTP.exe service, potentially leading to full compromise of the SAP DB host. The CVSS 2.0 vector indicates partial confidentiality, integrity and availability impact.
Attack surface
The flaw is reached over the network via HTTP requests to the SAP DB Web Server, with no authentication required per the AV:N/AC:L/Au:N vector. No user interaction is indicated in the description or vector.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.70004 (99.3rd percentile) and a SecurityFocus reference is tagged Exploit and Patch, indicating public exploit material exists.
What to do
- Apply the vendor patch referenced by the SecurityFocus BID 24773 entry or the corresponding SAP DB update as the first action.
- If patching is not immediately possible, restrict network access to the SAP DB Web Server (waHTTP.exe) to trusted hosts only.
- Disable or stop the SAP DB Web Server component if it is not required for business operations.
- Place the service behind a reverse proxy or WAF that can filter malformed cookie and query string values.
- Monitor vendor and CERT/CC advisories for updated guidance specific to the deployed SAP DB version.
Detection
- Inspect HTTP request logs for unusually long cookie values or query string parameters sent to waHTTP.exe endpoints.
- Monitor for crashes or restarts of waHTTP.exe, which can indicate failed overflow attempts.
- Use network IDS/IPS signatures for known SAP DB Web Server overflow patterns if available.
- Alert on unexpected outbound connections or child processes spawned by the waHTTP.exe service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3614 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3614), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.