ID

VAR-201409-1160


TITLE

SAP NetWeaver Dispatcher Integer Overflow Vulnerability

Trust: 0.8

sources: IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05481

DESCRIPTION

SAP NetWeaver is the technical foundation of SAP's integrated technology platform and all SAP applications since SAP Business Suite. An integer overflow vulnerability exists in SAP NetWeaver Dispatcher. An attacker exploits a vulnerability to conduct a denial of service attack

Trust: 0.72

sources: CNVD: CNVD-2014-05481 // IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05481

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.x

Trust: 0.8

sources: IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05481

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-05481
value: MEDIUM

Trust: 0.6

IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2014-05481
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05481

TYPE

Buffer error

Trust: 0.2

sources: IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d

PATCH

title:Patch for SAP NetWeaver Dispatcher Integer Overflow Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/49762

Trust: 0.6

sources: CNVD: CNVD-2014-05481

EXTERNAL IDS

db:CNVDid:CNVD-2014-05481

Trust: 0.8

db:OSVDBid:110610

Trust: 0.6

db:SECUNIAid:60488

Trust: 0.6

db:IVDid:E99BCE8A-1EC0-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: e99bce8a-1ec0-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-05481

REFERENCES

url:http://secunia.com/advisories/60488/

Trust: 0.6

url:http://osvdb.com/show/osvdb/110610

Trust: 0.6

sources: CNVD: CNVD-2014-05481

SOURCES

db:IVDid:e99bce8a-1ec0-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-05481

LAST UPDATE DATE

2022-05-17T02:09:04.423000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-05481date:2014-09-09T00:00:00

SOURCES RELEASE DATE

db:IVDid:e99bce8a-1ec0-11e6-abef-000c29c66e3ddate:2014-09-09T00:00:00
db:CNVDid:CNVD-2014-05481date:2014-09-06T00:00:00