Release date: 2013-03-12
Updated on: 2013-03-21
Affected Systems:
Sap net Weaver 7.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58612
SAP NetWeaver is a next-generation service-based platform that serves as the foundation for all future SAP applications.
SAP NetWeaver 7.30 and other versions have unknown details in Classification (CA-CL), through SMB Relay attack ), attackers can exploit this vulnerability to obtain arbitrary files in the file system of the SAP server.
<* Source: Nikolay Mescherin
Link: http://www.securelist.com/en/advisories/52699
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sap.com/platform/netweaver/index.epx