PT-2012-5341 · Sap · Sap Netweaver As Abap

CVE-2012-4341

·

Publicado

2012-08-15

·

Atualizado

2022-10-06

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP NetWeaver ABAP versions 7.x
Description The issue allows remote attackers to cause a denial of service and execute arbitrary code via a long parameter value, crafted string size field, or long Parameter Name string in a package with opcode 0x43 and sub opcode 0x4 to TCP port 3900, specifically targeting the msg server.exe component.
Recommendations For SAP NetWeaver ABAP version 7.x, apply the necessary patches or updates to fix the buffer overflows in msg server.exe. As a temporary workaround, consider restricting access to TCP port 3900 to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4341

Produtos afetados

Sap Netweaver As Abap