PT-2014-1951 · Sap · Sap Netweaver

Dmitry Chastukhin

·

Publicado

2014-11-06

·

Atualizado

2018-12-10

·

CVE-2015-2817

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver version 7.40
Description The issue allows remote attackers to obtain sensitive information. This can be achieved via the ReadProfile parameters in the SAP Management Console. Additionally, the vulnerability exists due to a lack of restrictions on remote function calls, specifically the GetSystemInstanceList function. An attacker can exploit this by sending a specially crafted SOAP request to gain information about the integration platform and operating system.
Recommendations For SAP NetWeaver version 7.40, consider restricting access to the GetSystemInstanceList function and limiting the use of the ReadProfile parameters until a patch is available. As a temporary workaround, disabling remote function calls for GetSystemInstanceList may help minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10123
CVE-2015-2817

Produtos afetados

Sap Netweaver