vendor:
SAP Message Server
by:
9
CVSS
CRITICAL
Remote heap-based buffer-overflow
119
CWE
Product Name: SAP Message Server
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
SAP Message Server Remote Heap-based Buffer Overflow Vulnerability
The SAP Message Server is vulnerable to a remote heap-based buffer overflow. The vulnerability occurs due to inadequate boundary checks on user-supplied data before copying it to a buffer of insufficient size. Remote attackers can exploit this vulnerability to execute arbitrary code with SYSTEM-level privileges. Successful attacks will result in a complete compromise of affected computers, while failed attacks may cause denial-of-service conditions disabling all functionality of the application.
Mitigation:
It is recommended to apply the latest patches and updates provided by the vendor to mitigate this vulnerability. Additionally, network-level controls such as firewalls can help prevent remote exploitation.