SAP NetWeaver Central User Administration Information Disclosure Vulnerability
BID:67448
Info
SAP NetWeaver Central User Administration Information Disclosure Vulnerability
| Bugtraq ID: | 67448 |
| Class: | Design Error |
| CVE: |
CVE-2014-3787 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2014 12:00AM |
| Updated: | May 21 2014 12:42AM |
| Credit: | Dmitry Gutsko of Positive Research Center |
| Vulnerable: |
SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 EHP2 SAP NetWeaver 7.0 EHP1 SAP NetWeaver 7.0 SAP NetWeaver 6.4 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver Central User Administration Information Disclosure Vulnerability
SAP NetWeaver is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
SAP NetWeaver 7.20 and prior are vulnerable.
SAP NetWeaver is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
SAP NetWeaver 7.20 and prior are vulnerable.
Exploit / POC
SAP NetWeaver Central User Administration Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
SAP NetWeaver Central User Administration Information Disclosure Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
SAP NetWeaver Central User Administration Information Disclosure Vulnerability
References:
References:
- Vendor Homepage (SAP)