PT-2013-4286 · Sap · Sap Netweaver
Bruno Morisson
·
Publicado
2013-08-16
·
Atualizado
2017-08-29
·
CVE-2013-3319
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Netweaver version 7.03
Description
The issue allows remote attackers to obtain sensitive information via a crafted SOAP request to the "TCP port 1128" endpoint, specifically targeting the
GetComputerSystem method in the HostControl service.Recommendations
For SAP Netweaver version 7.03, consider restricting access to the HostControl service or the
GetComputerSystem method to minimize the risk of exploitation.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver