SAP Text Conversion Module Remote Code Injection Vulnerability
BID:101800
Info
SAP Text Conversion Module Remote Code Injection Vulnerability
| Bugtraq ID: | 101800 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2017 12:00AM |
| Updated: | Dec 19 2017 10:00PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP CONVERT_TEXT 0 |
| Not Vulnerable: | |
Discussion
SAP Text Conversion Module Remote Code Injection Vulnerability
The Text Conversion Module for SAP is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
The Text Conversion Module for SAP is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
Solution / Fix
SAP Text Conversion Module Remote Code Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Text Conversion Module Remote Code Injection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2371726 (SAP)
- SAP Security Patch Day �?? November 2017 (SAP)