CVE-2003-1035: High severity SAP Sap R 3 vulnerability
Published Mar 16, 2004
·Updated
The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.
Affected Software
3 affected components
SAP Sap R 3
SAP SAPgui=4.6c
SAP SAPgui=4.6d
Event History
Mar 16, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1035?
CVE-2003-1035 has a medium severity rating as it allows attackers to bypass account locking mechanisms.
2
How do I fix CVE-2003-1035?
To fix CVE-2003-1035, ensure that appropriate security configurations are applied to limit RFC API access.
3
What systems are affected by CVE-2003-1035?
CVE-2003-1035 affects SAP R/3 version 46C and 46D installations.
4
Can CVE-2003-1035 lead to unauthorized access?
Yes, CVE-2003-1035 can lead to unauthorized access due to brute force password guessing attacks.
5
Is CVE-2003-1035 a common vulnerability?
CVE-2003-1035 is considered a notable vulnerability due to its exploitation potential in SAP R/3 systems.