lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 0.90% probability of being exploited in the next 30 days, ranking higher than 58% of all scored CVEs.