SAP Netweaver 'SAPHostControl' Service Remote Code Execution Vulnerability
BID:55084
Info
SAP Netweaver 'SAPHostControl' Service Remote Code Execution Vulnerability
| Bugtraq ID: | 55084 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2012 12:00AM |
| Updated: | May 10 2013 11:52AM |
| Credit: | Michael Jordon, Context Information Security |
| Vulnerable: |
SAP NetWeaver 7.02 |
| Not Vulnerable: | |
Discussion
SAP Netweaver 'SAPHostControl' Service Remote Code Execution Vulnerability
SAP Netweaver is prone to a remote code-execution vulnerability.
An attacker may leverage this issue to execute arbitrary script code with administrator user rights in context of the affected application. This may allow an attacker to take complete control of the system.
SAP NetWeaver 7.02 is vulnerable; other versions may also be affected.
SAP Netweaver is prone to a remote code-execution vulnerability.
An attacker may leverage this issue to execute arbitrary script code with administrator user rights in context of the affected application. This may allow an attacker to take complete control of the system.
SAP NetWeaver 7.02 is vulnerable; other versions may also be affected.
Exploit / POC
SAP Netweaver 'SAPHostControl' Service Remote Code Execution Vulnerability
An attacker can use a web browser to exploit this issue.
Exploit is available. Please see the references for information.
The following metasploit exploit modules are available:
An attacker can use a web browser to exploit this issue.
Exploit is available. Please see the references for information.
The following metasploit exploit modules are available:
Solution / Fix
SAP Netweaver 'SAPHostControl' Service Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SAP Netweaver 'SAPHostControl' Service Remote Code Execution Vulnerability
References:
References:
- SAP NetWeaver Homepage (SAP)