SAP Web Application Server Unspecified Remote Buffer Overflow Vulnerability
BID:37871
Info
SAP Web Application Server Unspecified Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 37871 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2010 12:00AM |
| Updated: | Jan 19 2010 12:00AM |
| Credit: | Onapsis Research Lab |
| Vulnerable: |
SAP Kernel 7.01 SAP Kernel 7.00 SAP Kernel 6.40 |
| Not Vulnerable: | |
Discussion
SAP Web Application Server Unspecified Remote Buffer Overflow Vulnerability
SAP Web Application Server is prone to an unspecified remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will crash the application.
The following components are vulnerable:
SAP Kernel 6.40 prior to patch level 312
SAP Kernel 7.00 prior to patch level 235
SAP Kernel 7.01 prior to patch level 72
SAP Web Application Server is prone to an unspecified remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will crash the application.
The following components are vulnerable:
SAP Kernel 6.40 prior to patch level 312
SAP Kernel 7.00 prior to patch level 235
SAP Kernel 7.01 prior to patch level 72
Exploit / POC
SAP Web Application Server Unspecified Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Web Application Server Unspecified Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.