Vulnerabilities > CVE-2013-1593 - Improper Validation of Array Index vulnerability in SAP Netweaver

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
sap
CWE-129

Summary

A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN.

Vulnerable Configurations

Part Description Count
Application
Sap
4

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Overflow Buffers
    Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an attacker. As a consequence, an attacker is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the attackers' choice.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/120350/CORE-2012-1128.txt
idPACKETSTORM:120350
last seen2016-12-05
published2013-02-15
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/120350/SAP-Netweaver-Message-Server-Buffer-Overflow.html
titleSAP Netweaver Message Server Buffer Overflow

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:78223
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-78223
titleSAP Netweaver Message Server Multiple Vulnerabilities