First published: Tue Mar 16 2004(Updated: )
Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Internet Transaction Server | <=6.20_pl7 | |
SAP Internet Transaction Server | <=4.6_pl463 | |
SAP Internet Transaction Server | <=6.10_pl30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1037 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2003-1037, you should update your SAP Internet Transaction Server to a patched version provided by SAP.
CVE-2003-1037 affects various versions of SAP Internet Transaction Server, including versions up to 6.20_pl7, 4.6_pl463, and 6.10_pl30.
CVE-2003-1037 exploits the format string vulnerability through elevated trace levels, allowing execution of arbitrary code by attackers.
Yes, CVE-2003-1037 can be exploited remotely, which poses significant risk to affected systems.