CVE-2012-4341
Multiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) long parameter value, (2) crafted string size field, or (3) long Parameter Name string in a package with opcode 0x43 and sub opcode 0x4 to TCP port 3900.
- Affected products
- Sap Netweaver As Abap
- Sap Netweaver Abap
- = 7.0, 7.02, 7.03
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 8.7% (95th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2012-08-15
CVE-2012-4341 at NVD
2 known exploits for CVE-2012-4341
Proof-of-concept code and exploit modules indexed by Sploitus