ID

VAR-201506-0095


CVE

CVE-2015-5067


TITLE

SAP NetWeaver of Cross-System Tools and Data Transfer Workbench Vulnerabilities that gain access

Trust: 0.8

sources: JVNDB: JVNDB-2015-003264

DESCRIPTION

The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors, aka SAP Security Notes 2059659 and 2057982. Vendors have confirmed this vulnerability SAP Security Note 2059659 and 2057982 It is released as.Access may be obtained by a third party. SAP NetWeaver is prone to multiple local security-bypass vulnerabilities. Local attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions

Trust: 1.89

sources: NVD: CVE-2015-5067 // JVNDB: JVNDB-2015-003264 // BID: 75165

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion: -

Trust: 1.6

vendor:sapmodel:netweaverscope: - version: -

Trust: 0.8

vendor:sapmodel:netweaverscope:eqversion:0

Trust: 0.3

sources: BID: 75165 // JVNDB: JVNDB-2015-003264 // CNNVD: CNNVD-201506-501 // NVD: CVE-2015-5067

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-5067
value: HIGH

Trust: 1.0

NVD: CVE-2015-5067
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201506-501
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2015-5067
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2015-003264 // CNNVD: CNNVD-201506-501 // NVD: CVE-2015-5067

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.8

sources: JVNDB: JVNDB-2015-003264 // NVD: CVE-2015-5067

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201506-501

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201506-501

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003264

PATCH

title:SAP Security Note 2059659,2057982url:http://scn.sap.com/docs/DOC-55451

Trust: 0.8

title:SAP Security Notes June 2015url:http://scn.sap.com/community/security/blog/2015/06/11/sap-security-notes-june-2015

Trust: 0.8

sources: JVNDB: JVNDB-2015-003264

EXTERNAL IDS

db:NVDid:CVE-2015-5067

Trust: 2.7

db:BIDid:75165

Trust: 1.3

db:PACKETSTORMid:133515

Trust: 1.0

db:PACKETSTORMid:133516

Trust: 1.0

db:JVNDBid:JVNDB-2015-003264

Trust: 0.8

db:CNNVDid:CNNVD-201506-501

Trust: 0.6

sources: BID: 75165 // JVNDB: JVNDB-2015-003264 // CNNVD: CNNVD-201506-501 // NVD: CVE-2015-5067

REFERENCES

url:http://scn.sap.com/community/security/blog/2015/06/11/sap-security-notes-june-2015

Trust: 1.6

url:http://erpscan.com/advisories/erpscan-15-016-sap-netweaver-hardcoded-credentials/

Trust: 1.4

url:http://packetstormsecurity.com/files/133516/sap-netweaver-as-lsct1i13-abap-hardcoded-credentials.html

Trust: 1.0

url:http://www.securityfocus.com/bid/75165

Trust: 1.0

url:https://erpscan.io/advisories/erpscan-15-016-sap-netweaver-hardcoded-credentials/

Trust: 1.0

url:http://packetstormsecurity.com/files/133515/sap-netweaver-as-fkcdbftrace-abap-hardcoded-credentials.html

Trust: 1.0

url:https://erpscan.io/advisories/erpscan-15-015-sap-netweaver-hardcoded-credentials/

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-5067

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-5067

Trust: 0.8

sources: JVNDB: JVNDB-2015-003264 // CNNVD: CNNVD-201506-501 // NVD: CVE-2015-5067

CREDITS

Vahagn Vardanyan, Rustem Gazizov, and Diana Grigorieva of ERPScan.

Trust: 0.3

sources: BID: 75165

SOURCES

db:BIDid:75165
db:JVNDBid:JVNDB-2015-003264
db:CNNVDid:CNNVD-201506-501
db:NVDid:CVE-2015-5067

LAST UPDATE DATE

2024-11-23T23:02:41.051000+00:00


SOURCES UPDATE DATE

db:BIDid:75165date:2015-07-15T01:00:00
db:JVNDBid:JVNDB-2015-003264date:2015-10-05T00:00:00
db:CNNVDid:CNNVD-201506-501date:2015-06-25T00:00:00
db:NVDid:CVE-2015-5067date:2024-11-21T02:32:15.657

SOURCES RELEASE DATE

db:BIDid:75165date:2015-06-11T00:00:00
db:JVNDBid:JVNDB-2015-003264date:2015-06-25T00:00:00
db:CNNVDid:CNNVD-201506-501date:2015-06-25T00:00:00
db:NVDid:CVE-2015-5067date:2015-06-24T14:59:09.033