PT-2004-1213 · Sap · Sap R/3

Published

2004-03-16

·

Updated

2018-10-19

·

CVE-2003-1035

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP R/3 version 46C/D
Description The issue allows remote attackers to bypass account locking by using the RFC API for brute force password guessing attacks, which does not lock out the account like the SAPGUI does.
Recommendations For SAP R/3 version 46C/D, consider restricting access to the RFC API to minimize the risk of exploitation. As a temporary workaround, implement additional account lockout measures outside of the SAPGUI to prevent brute force attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1035

Affected Products

Sap R/3