The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Maxdb | Mysql | 7.5.00 (including) | 7.5.00 (including) |
Maxdb | Mysql | 7.5.00.08 (including) | 7.5.00.08 (including) |
Maxdb | Mysql | 7.5.00.11 (including) | 7.5.00.11 (including) |
Maxdb | Mysql | 7.5.00.12 (including) | 7.5.00.12 (including) |
Maxdb | Mysql | 7.5.00.14 (including) | 7.5.00.14 (including) |
Maxdb | Mysql | 7.5.00.15 (including) | 7.5.00.15 (including) |
Maxdb | Mysql | 7.5.00.16 (including) | 7.5.00.16 (including) |
Maxdb | Mysql | 7.5.00.18 (including) | 7.5.00.18 (including) |
Maxdb | Mysql | 7.5.00.19 (including) | 7.5.00.19 (including) |