CVE-2013-7364

An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and write to arbitrary files via unknown vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:netweaver:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:00

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2013-02/0133.html - () http://archives.neohapsis.com/archives/bugtraq/2013-02/0133.html -
References () http://scn.sap.com/docs/DOC-8218 - () http://scn.sap.com/docs/DOC-8218 -
References () http://www.onapsis.com/get.php?resid=adv_onapsis-2013-004 - () http://www.onapsis.com/get.php?resid=adv_onapsis-2013-004 -
References () http://www.onapsis.com/research-advisories.php - () http://www.onapsis.com/research-advisories.php -
References () https://service.sap.com/sap/support/notes/1682613 - () https://service.sap.com/sap/support/notes/1682613 -

Information

Published : 2014-04-10 20:55

Updated : 2024-11-21 02:00


NVD link : CVE-2013-7364

Mitre link : CVE-2013-7364

CVE.ORG link : CVE-2013-7364


JSON object : View

Products Affected

sap

  • netweaver
CWE
CWE-264

Permissions, Privileges, and Access Controls