PT-2004-1213 · Sap · Sap R/3

Publicado

2004-03-16

·

Atualizado

2018-10-19

·

CVE-2003-1035

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP R/3 version 46C/D
Description The issue allows remote attackers to bypass account locking by using the RFC API for brute force password guessing attacks, which does not lock out the account like the SAPGUI does.
Recommendations For SAP R/3 version 46C/D, consider restricting access to the RFC API to minimize the risk of exploitation. As a temporary workaround, implement additional account lockout measures outside of the SAPGUI to prevent brute force attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1035

Produtos afetados

Sap R/3