ID

VAR-190001-0887


TITLE

SAP WebAS 'cachetest' Service denial of service vulnerability

Trust: 1.1

sources: IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-3704 // BID: 49645

DESCRIPTION

SAP Web Application Server (sometimes called WebAS) is the runtime environment for SAP applications - all mySAP Business Suite solutions (SRM, CRM, SCM, PLM, ERP) run on SAP WebAS. The SAP Web Application Server provides an input validation vulnerability for the 'cachetest' service. An unauthenticated attacker can exploit the vulnerability to remotely destroy the SAP Web Application Server, causing a denial of service attack. SAP WebAS is prone to a denial-of-service vulnerability. Attackers may leverage this issue to crash the affected application, denying service to legitimate users

Trust: 0.99

sources: CNVD: CNVD-2011-3704 // BID: 49645 // IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-3704

AFFECTED PRODUCTS

vendor:sapmodel:web application serverscope:eqversion:7.0

Trust: 1.1

sources: IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-3704 // BID: 49645

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201109-256

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201109-256

PATCH

title:SAP WebAS 'cachetest' service denial of service vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/5099

Trust: 0.6

sources: CNVD: CNVD-2011-3704

EXTERNAL IDS

db:BIDid:49645

Trust: 1.5

db:CNVDid:CNVD-2011-3704

Trust: 0.8

db:CNNVDid:CNNVD-201109-256

Trust: 0.6

db:IVDid:31394EC6-1F88-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 31394ec6-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-3704 // BID: 49645 // CNNVD: CNNVD-201109-256

REFERENCES

url:http://seclists.org/fulldisclosure/2011/sep/129

Trust: 0.6

url:http://www.securityfocus.com/bid/49645

Trust: 0.6

url:http://www.sap.com/

Trust: 0.3

url:msg://bugtraq//4e71e847.6020607@onapsis.com

Trust: 0.3

url:http://www.onapsis.com/get.php?resid=adv_onapsis-2011-014

Trust: 0.3

url:https://service.sap.com/sap/support/notes/1553930

Trust: 0.3

sources: CNVD: CNVD-2011-3704 // BID: 49645 // CNNVD: CNNVD-201109-256

CREDITS

Mariano Nuez Di Croce

Trust: 0.9

sources: BID: 49645 // CNNVD: CNNVD-201109-256

SOURCES

db:IVDid:31394ec6-1f88-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-3704
db:BIDid:49645
db:CNNVDid:CNNVD-201109-256

LAST UPDATE DATE

2022-05-17T02:07:53.866000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-3704date:2011-09-16T00:00:00
db:BIDid:49645date:2011-09-15T00:00:00
db:CNNVDid:CNNVD-201109-256date:2011-09-19T00:00:00

SOURCES RELEASE DATE

db:IVDid:31394ec6-1f88-11e6-abef-000c29c66e3ddate:2011-09-16T00:00:00
db:CNVDid:CNVD-2011-3704date:2011-09-16T00:00:00
db:BIDid:49645date:2011-09-15T00:00:00
db:CNNVDid:CNNVD-201109-256date:1900-01-01T00:00:00