Release date: 2011-11-11
Updated on: 2011-11-23
Affected Systems:
SAP NetWeaver
Description:
--------------------------------------------------------------------------------
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
The implementation of SAP rstxforwarreport has the path traversal vulnerability, which can cause SMB relay attacks and full control system.
<* Source: Dmitriy Chastuchin
Link: http://erpscan.com/advisories/dsecrg-11-038-sap-rstxscrp-report-smb-relay-vulnerability/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
SAP has released a Security Bulletin (DSECRG-11-038) and patches for this:
DSECRG-11-038: SAP rstx1_report-Smb Relay Vulnerability
Link: http://erpscan.com/advisories/dsecrg-11-038-sap-rstxscrp-report-smb-relay-vulnerability/