Release date:
Updated on:
Affected Systems:
Sap net Weaver 7.02
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55084
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
SAP NetWeaver 7.02 and other versions have a remote code execution vulnerability. Attackers can exploit this vulnerability to execute arbitrary script code in affected applications with administrator privileges to completely control the affected systems.
<* Source: Michael Jordon (disclosure@contextis.co.uk)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sap.com/platform/netweaver/index.epx