PT-2014-5105 · Sap · Sap Netweaver Application Server Abap

Published

2014-04-30

·

Updated

2014-05-10

·

CVE-2014-3130

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP Netweaver ABAP Application Server (affected versions not specified)
Description The issue concerns the ABAP Help documentation and translation tools (BC-DOC-HLP) in SAP Netweaver ABAP Application Server, where access is not properly restricted. This allows local users to gain privileges and execute ABAP instructions via crafted help messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3130

Affected Products

Sap Netweaver Application Server Abap