← Vulnerability feed

Vulnerability record · CVE-2007-3614 · published 6 July 2007

CVE-2007-3614: SAP DB Web Server waHTTP.exe stack buffer overflow

Sap · Sap Db

waHTTP.exe, the SAP DB Web Server component, contains multiple stack-based buffer overflows reachable through HTTP request fields such as a cookie value and an additional parameter tied to sapdbwa_GetQueryString, plus other unspecified fields. Successful exploitation allows remote code execution on the database web server, which is a serious exposure for any internet- or network-reachable SAP DB deployment.

7.5 CVSS 2.0 High EPSS 70% · top 0.6%
7.5CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with a very high EPSS score and public exploit references, though no confirmed active exploitation in KEV.

What it is

waHTTP.exe, the SAP DB Web Server component, contains multiple stack-based buffer overflows reachable through HTTP request fields such as a cookie value and an additional parameter tied to sapdbwa_GetQueryString, plus other unspecified fields. Successful exploitation allows remote code execution on the database web server, which is a serious exposure for any internet- or network-reachable SAP DB deployment.

Impact

A remote attacker can execute arbitrary code with the privileges of the waHTTP.exe service, potentially leading to full compromise of the SAP DB host. The CVSS 2.0 vector indicates partial confidentiality, integrity and availability impact.

Attack surface

The flaw is reached over the network via HTTP requests to the SAP DB Web Server, with no authentication required per the AV:N/AC:L/Au:N vector. No user interaction is indicated in the description or vector.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.70004 (99.3rd percentile) and a SecurityFocus reference is tagged Exploit and Patch, indicating public exploit material exists.

What to do

  • Apply the vendor patch referenced by the SecurityFocus BID 24773 entry or the corresponding SAP DB update as the first action.
  • If patching is not immediately possible, restrict network access to the SAP DB Web Server (waHTTP.exe) to trusted hosts only.
  • Disable or stop the SAP DB Web Server component if it is not required for business operations.
  • Place the service behind a reverse proxy or WAF that can filter malformed cookie and query string values.
  • Monitor vendor and CERT/CC advisories for updated guidance specific to the deployed SAP DB version.

Detection

  • Inspect HTTP request logs for unusually long cookie values or query string parameters sent to waHTTP.exe endpoints.
  • Monitor for crashes or restarts of waHTTP.exe, which can indicate failed overflow attempts.
  • Use network IDS/IPS signatures for known SAP DB Web Server overflow patterns if available.
  • Alert on unexpected outbound connections or child processes spawned by the waHTTP.exe service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3614 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2003-0939Sap db vulnerabilityeo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code vi…EPSS 3.1%7.5CVE-2003-0941Sap db vulnerabilityweb-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct reque…EPSS 1.5%7.5CVE-2003-0942Sap db vulnerabilityBuffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a …EPSS 2.7%7.5CVE-2003-0943Sap db vulnerabilityweb-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially …EPSS 1.5%7.5CVE-2003-0944Sap db vulnerabilityBuffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL wit…EPSS 2.7%7.5CVE-2003-0945Sap db vulnerabilityThe Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unautho…EPSS 1.5%7.2CVE-2002-1576Sap db vulnerabilitylserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain pri…EPSS 0.90%7.2CVE-2003-1033Sap db vulnerabilityThe (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2007-3614), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.