PT-2020-7096 · Sap · Sap Netweaver
Published
2020-02-05
·
Updated
2020-02-07
·
CVE-2011-1517
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver version 7.0
Description
The issue is caused by an error in the
DiagTraceHex() function, allowing Remote Code Execution and Denial of Service. An attacker could exploit this by sending a specially-crafted packet, causing the application to crash.Recommendations
For SAP NetWeaver version 7.0, as a temporary workaround, consider disabling the
DiagTraceHex() function until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Netweaver