Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SAP 未限制进程执行权漏洞
Vulnerability Description
SAP 6.4的6.40补丁4之前版本、6.2的6.20补丁1364之前版本、4.6的4.6D补丁1767之前版本、45的45B补丁913之前版本、40的40B补丁1008之前版本和31的31I补丁735之前版本未能正确地限制lnaxdm/sapsys的进程执行权,远程攻击者可通过特定的、以本地可执行文件名结尾的UDP包来执行任意代码,又称为"FX SAP R/3 gwrd vuln"。
CVSS Information
N/A
Vulnerability Type
N/A