Vulnerabilities > CVE-2016-5845 - Local Privilege Escalation and Denial of Service vulnerability in SAP Sapcar

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
local
low complexity
sap
exploit available

Summary

SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (program crash) via an invalid file name in an archive file, aka SAP Security Note 2312905. <a href="http://cwe.mitre.org/data/definitions/252.html">CWE-252: Unchecked Return Value</a>

Vulnerable Configurations

Part Description Count
Application
Sap
1

Exploit-Db

descriptionSAP SAPCAR - Multiple Vulnerabilities. CVE-2016-5845,CVE-2016-5847. Dos exploit for Linux platform
fileexploits/linux/dos/40230.txt
idEDB-ID:40230
last seen2016-08-10
modified2016-08-10
platformlinux
port
published2016-08-10
reporterCore Security
titleSAP SAPCAR - Multiple Vulnerabilities
typedos

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/138284/CORE-2016-0006.txt
idPACKETSTORM:138284
last seen2016-12-05
published2016-08-11
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/138284/SAP-CAR-Archive-Tool-Denial-Of-Service-Security-Bypass.html
titleSAP CAR Archive Tool Denial Of Service / Security Bypass