SAP ERP Central Component 'CJDB_FILL_MEMORY_FROM_PPB()' Function Remote Code Injection Vulnerability
BID:59677
Info
SAP ERP Central Component 'CJDB_FILL_MEMORY_FROM_PPB()' Function Remote Code Injection Vulnerability
| Bugtraq ID: | 59677 |
| Class: | Design Error |
| CVE: |
CVE-2013-3244 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2013 12:00AM |
| Updated: | May 07 2013 12:00AM |
| Credit: | Ertunga Arsal |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SAP ERP Central Component 'CJDB_FILL_MEMORY_FROM_PPB()' Function Remote Code Injection Vulnerability
SAP ERP Central Component is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Authenticated attackers can exploit this issue to inject or execute arbitrary code in the context of the affected application.
SAP ERP Central Component is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Authenticated attackers can exploit this issue to inject or execute arbitrary code in the context of the affected application.
Exploit / POC
SAP ERP Central Component 'CJDB_FILL_MEMORY_FROM_PPB()' Function Remote Code Injection Vulnerability
An exploit for this vulnerability is available in ESNC Penetration Testing Suite. This exploit is not otherwise publicly available.
An exploit for this vulnerability is available in ESNC Penetration Testing Suite. This exploit is not otherwise publicly available.
Solution / Fix
SAP ERP Central Component 'CJDB_FILL_MEMORY_FROM_PPB()' Function Remote Code Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP ERP Central Component 'CJDB_FILL_MEMORY_FROM_PPB()' Function Remote Code Injection Vulnerability
References:
References:
- SAP Homepage (SAP)