CVE detail
CVE-2001-0366 — CVE-2001-0366
Published 2001-06-27 · Modified 2026-06-16 · Vendor sap · Product sap_r_3_web_application_server_demo · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0056
EPSS probability
exploitation probability, 30d
43.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References