ID

VAR-201011-0282


TITLE

SAP NetWeaver Security Bypass Denial of Service Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2010-2861 // BID: 44903

DESCRIPTION

SAP NetWeaver is the technical foundation for SAP Business Suite solutions, SAP xApps composite applications, partner solutions, and custom applications. The SAP Netweaver Metamodel Repository is accessible by default in the old SAP ECC version without authentication. The attacker can access the test performance page: http://sapserver:8000/mmr/MMR?page=MMRPerformance if used max. Data size for performance testing, the server will consume 100% CPU. The attacker writes a script that calls this script 100, and the server will not respond for a long time. SAP NetWeaver is prone to a remote denial-of-service vulnerability An attacker can exploit this issue to cause a high CPU load and make the application unresponsive, denying service to legitimate users

Trust: 0.99

sources: CNVD: CNVD-2010-2861 // BID: 44903 // IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2861

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 1.1

sources: IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2861 // BID: 44903

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 44903

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 44903

PATCH

title:SAP NetWeaver Security bypasses denial of service vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/1775

Trust: 0.6

sources: CNVD: CNVD-2010-2861

EXTERNAL IDS

db:BIDid:44903

Trust: 0.9

db:CNVDid:CNVD-2010-2861

Trust: 0.8

db:IVDid:91C4D682-1FA8-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 91c4d682-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2861 // BID: 44903

REFERENCES

url:http://dsecrg.com/pages/vul/show.php?id=206http

Trust: 0.6

url:http://dsecrg.com/pages/vul/show.php?id=206

Trust: 0.3

url:http://www.sap.com/platform/netweaver/index.epx

Trust: 0.3

url:https://service.sap.com/sap/support/notes/1484097

Trust: 0.3

sources: CNVD: CNVD-2010-2861 // BID: 44903

CREDITS

Alexandr Polyakov from Digital Security Research Group [DSecRG]

Trust: 0.3

sources: BID: 44903

SOURCES

db:IVDid:91c4d682-1fa8-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2010-2861
db:BIDid:44903

LAST UPDATE DATE

2022-05-17T01:48:45.065000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-2861date:2010-11-18T00:00:00
db:BIDid:44903date:2010-11-17T00:00:00

SOURCES RELEASE DATE

db:IVDid:91c4d682-1fa8-11e6-abef-000c29c66e3ddate:2010-11-18T00:00:00
db:CNVDid:CNVD-2010-2861date:2010-11-18T00:00:00
db:BIDid:44903date:2010-11-17T00:00:00