ID

VAR-200907-0583


TITLE

SAP NetWeaver Password Information Disclosure Vulnerability

Trust: 0.3

sources: BID: 35729

DESCRIPTION

SAP NetWeaver is prone to an information-disclosure vulnerability because it fails to properly secure communication channels between clients and servers. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.

Trust: 0.3

sources: BID: 35729

AFFECTED PRODUCTS

vendor:sapmodel:ag sapgui patch levelscope:eqversion:7.109

Trust: 0.6

vendor:sapmodel:ag sapgui patch levelscope:eqversion:7.108

Trust: 0.3

vendor:sapmodel:ag sapguiscope:eqversion:0

Trust: 0.3

vendor:sapmodel:netweaver application server sp21scope:eqversion:6.40104329.313

Trust: 0.3

vendor:sapmodel:ag sapgui patch levelscope:eqversion:6.4029

Trust: 0.3

vendor:sapmodel:ag sapgui patch levelscope:eqversion:7.105

Trust: 0.3

vendor:sapmodel:netweaver application server sp17scope:eqversion:6.40104329.313

Trust: 0.3

vendor:sapmodel:sapgui d for windowsscope:eqversion:4.6

Trust: 0.3

vendor:sapmodel:netweaver portal sp21scope:eqversion:2004

Trust: 0.3

vendor:sapmodel:netweaver application server sp17scope:eqversion:6.40

Trust: 0.3

vendor:sapmodel:netweaver nw04s sp9scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver nw04 sp17scope: - version: -

Trust: 0.3

vendor:sapmodel:gui for windows patch levelscope:eqversion:6.2072

Trust: 0.3

vendor:sapmodel:netweaver portalscope:eqversion:2004..

Trust: 0.3

vendor:sapmodel:netweaver nw04 sp15scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver sp15scope:eqversion:7.0

Trust: 0.3

vendor:sapmodel:sapgui final release patchscope:eqversion:6406403.3.11.1004

Trust: 0.3

vendor:sapmodel:guiscope:eqversion:7.10

Trust: 0.3

vendor:sapmodel:gui for windows patch levelscope:eqversion:7.006

Trust: 0.3

vendor:sapmodel:netweaver nw04s sp10scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver sp20scope:eqversion:640

Trust: 0.3

vendor:sapmodel:netweaver nw04s sp8scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver nw04s sp11scope: - version: -

Trust: 0.3

vendor:sapmodel:sapgui c for windowsscope:eqversion:4.6

Trust: 0.3

vendor:sapmodel:ag sapguiscope:eqversion:6.4

Trust: 0.3

vendor:sapmodel:gui for windows patch levelscope:eqversion:6.4030

Trust: 0.3

vendor:sapmodel:netweaver developer studio sp21scope:eqversion:2004

Trust: 0.3

vendor:sapmodel:netweaver nw04s sp7scope: - version: -

Trust: 0.3

vendor:sapmodel:gui plscope:eqversion:7.10

Trust: 0.3

vendor:sapmodel:netweaver nw04 sp19scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver nw04 sp18scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver sp8scope:eqversion:7.0

Trust: 0.3

vendor:sapmodel:gui patchscope:eqversion:6.4029

Trust: 0.3

vendor:sapmodel:sapgui b for windowsscope:eqversion:4.6

Trust: 0.3

vendor:sapmodel:netweaver nw04 sp16scope: - version: -

Trust: 0.3

vendor:sapmodel:netweaver portal sp17scope:eqversion:2004

Trust: 0.3

vendor:sapmodel:sapgui for windowsscope:eqversion:4.6

Trust: 0.3

vendor:sapmodel:sapgui a for windowsscope:eqversion:4.6

Trust: 0.3

vendor:sapmodel:netweaver developer studio sp17scope:eqversion:-2004

Trust: 0.3

sources: BID: 35729

THREAT TYPE

network

Trust: 0.3

sources: BID: 35729

TYPE

Design Error

Trust: 0.3

sources: BID: 35729

EXTERNAL IDS

db:BIDid:35729

Trust: 0.3

sources: BID: 35729

REFERENCES

url:http://www.secaron.de/content/presse/fachartikel/sniffing_diag.pdf

Trust: 0.3

url:http://www.sap.com/platform/netweaver/index.epx

Trust: 0.3

sources: BID: 35729

CREDITS

Andreas Baus and Rene Ledosquet from Secaron AG

Trust: 0.3

sources: BID: 35729

SOURCES

db:BIDid:35729

LAST UPDATE DATE

2022-05-17T01:41:46.141000+00:00


SOURCES UPDATE DATE

db:BIDid:35729date:2009-07-17T21:16:00

SOURCES RELEASE DATE

db:BIDid:35729date:2009-07-17T00:00:00