SAP NetWeaver RFC Function Arbitrary File Disclosure Vulnerability
BID:59501
Info
SAP NetWeaver RFC Function Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 59501 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2013 12:00AM |
| Updated: | Apr 25 2013 12:00AM |
| Credit: | Nikolay Mescherin (ERPScan) |
| Vulnerable: |
SAP NetWeaver 7.30 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver RFC Function Arbitrary File Disclosure Vulnerability
SAP NetWeaver is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can exploit this issue to disclose arbitrary files in the context of the application. This may aid in further attacks.
SAP NetWeaver 7.30 is vulnerable; other versions may also be affected.
SAP NetWeaver is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can exploit this issue to disclose arbitrary files in the context of the application. This may aid in further attacks.
SAP NetWeaver 7.30 is vulnerable; other versions may also be affected.
Exploit / POC
SAP NetWeaver RFC Function Arbitrary File Disclosure Vulnerability
Attackers can exploit this issue with a browser.
Attackers can exploit this issue with a browser.
Solution / Fix
SAP NetWeaver RFC Function Arbitrary File Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP NetWeaver RFC Function Arbitrary File Disclosure Vulnerability
References:
References:
- [DSECRG-13-011] SAP NetWeaver PFL �?? SMB Relay (ERPScan Research Group)
- SAP Homepage (SAP)