Lucene search

K
cve[email protected]CVE-2012-4341
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4341

2022-10-0316:15:32
CWE-119
web.nvd.nist.gov
23
cve-2012-4341
buffer overflow
sap netweaver abap
remote code execution
denial of service
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.088 Low

EPSS

Percentile

94.6%

Multiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) long parameter value, (2) crafted string size field, or (3) long Parameter Name string in a package with opcode 0x43 and sub opcode 0x4 to TCP port 3900.

Affected configurations

NVD
Node
sapnetweaver_abapMatch7.0
OR
sapnetweaver_abapMatch7.02sp6
OR
sapnetweaver_abapMatch7.03sp4

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.088 Low

EPSS

Percentile

94.6%

Related for CVE-2012-4341