The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages.
References
Configurations
History
21 Nov 2024, 02:07
Type | Values Removed | Values Added |
---|---|---|
References | () http://scn.sap.com/docs/DOC-8218 - | |
References | () http://seclists.org/fulldisclosure/2014/Apr/302 - | |
References | () http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-009 - | |
References | () http://www.securityfocus.com/bid/67108 - | |
References | () https://service.sap.com/sap/support/notes/1910914 - |
Information
Published : 2014-04-30 14:22
Updated : 2024-11-21 02:07
NVD link : CVE-2014-3130
Mitre link : CVE-2014-3130
CVE.ORG link : CVE-2014-3130
JSON object : View
Products Affected
sap
- netweaver_abap_application_server
CWE
CWE-264
Permissions, Privileges, and Access Controls