PT-2020-7096 · Sap · Sap Netweaver

Published

2020-02-05

·

Updated

2020-02-07

·

CVE-2011-1517

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP NetWeaver version 7.0
Description The issue is caused by an error in the DiagTraceHex() function, allowing Remote Code Execution and Denial of Service. An attacker could exploit this by sending a specially-crafted packet, causing the application to crash.
Recommendations For SAP NetWeaver version 7.0, as a temporary workaround, consider disabling the DiagTraceHex() function until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-1517

Affected Products

Sap Netweaver