First published: Tue Apr 10 2007(Updated: )
The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP RFC Library | =6.4 | |
SAP RFC Library | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1914 is categorized with a medium severity due to the potential exposure of sensitive RFC server configuration data.
To mitigate CVE-2007-1914, update the SAP RFC Library to versions 6.40 or 7.00 after the 20061211 patch.
The vulnerability primarily affects users of SAP RFC Library versions 6.40 and 7.00 before the specified patch release.
CVE-2007-1914 allows remote attackers to obtain sensitive configuration data from the RFC server.
CVE-2007-1914 is not a new vulnerability; it is distinct from CVE-2006-6010 but leverages similar attack vectors.