First published: Tue Apr 10 2007(Updated: )
The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM RACF | ||
Apple iOS and macOS | ||
HPE HP-UX | ||
HP Tru64 | ||
IBM AIX | ||
IBM OS/400 | =gold | |
IBM OS/400 | =v5r2m0 | |
Linux Kernel | ||
Microsoft Windows Server | ||
Siemens Reliant Unix | ||
Oracle Solaris SPARC | ||
SAP RFC Library | =6.4 | |
SAP RFC Library | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1913 has been assessed as having a moderate severity level due to its potential for unauthorized user and group enumeration.
To mitigate CVE-2007-1913, it is recommended to apply the latest security patches for the SAP RFC Library and restrict access to the affected system.
CVE-2007-1913 specifically affects SAP RFC Library versions 6.4 and 7.0 prior to December 11, 2006.
CVE-2007-1913 can be exploited by remote attackers who leverage the vulnerability to verify the existence of users and groups on the affected systems.
CVE-2007-1913 is recognized as a vulnerability primarily in legacy versions of the SAP RFC Library and may not affect systems with updated software.