SAP NetWeaver Dispatcher DiagTraceR3Info Function Arbitrary Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
SAP NetWeaver Dispatcher EHP2
SAP NetWeaver Dispatcher 7.0 EHP1
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-2611
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
SAP NetWeaver 7.0 EHP1, EHP2 dispatcher's disp?work.exe 7010.29.15.58313, And the DiagTraceR3Info function of the Dialog processor within the region have multiple security vulnerabilities. After a Developer Trace configuration is enabled, the specially crafted SAP Diag message is used, attackers can execute arbitrary code remotely.
<* Source: vendor
Link: http://www.securitytracker.com/id? 1027052
Http://www.coresecurity.com/content/sap-netweaver-dispatcher-multiple-vulnerabilities
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sap.com/