SAP Management Console NULL Pointer Dereference Denial of Service Vulnerability
BID:43548
Info
SAP Management Console NULL Pointer Dereference Denial of Service Vulnerability
| Bugtraq ID: | 43548 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2010 12:00AM |
| Updated: | Sep 27 2010 12:00AM |
| Credit: | Jordan Santarsieri from Onapsis |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SAP Management Console NULL Pointer Dereference Denial of Service Vulnerability
SAP Management Console is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to trigger a NULL-pointer dereference and disrupt the main management interface, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible; this has not been confirmed.
SAP Management Console 6.40, 7.00, and 7.10 are vulnerable; other versions may also be affected.
SAP Management Console is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to trigger a NULL-pointer dereference and disrupt the main management interface, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible; this has not been confirmed.
SAP Management Console 6.40, 7.00, and 7.10 are vulnerable; other versions may also be affected.
Exploit / POC
SAP Management Console NULL Pointer Dereference Denial of Service Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
References
SAP Management Console NULL Pointer Dereference Denial of Service Vulnerability
References:
References:
- ONAPSIS-2010-007: SAP Management Console Multiple Denial of Service (Onapsis S.R.L.)
- SAP Homepage (SAP)
- SAP Notes 1151410 (SAP)
- SAP Notes 1469804 (SAP)