Release date:
Updated on:
Affected Systems:
Sap net Weaver 7.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59501
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
An Arbitrary File leakage vulnerability exists in SAP NetWeaver 7.30 and other versions. This vulnerability is caused by an error in processing SPFC packets by an RFC function, attackers can exploit this vulnerability to gain access to arbitrary files on the SAP server.
<* Source: Nikolay Mescherin
Link: http://secunia.com/advisories/53198/
Http://erpscan.com/advisories/dsecrg-13-011-sap-netweaver-pfl-smb-relay/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sap.com/platform/netweaver/index.epx