First published: Wed Feb 05 2020(Updated: )
SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1517 is a vulnerability in SAP NetWeaver 7.0 that allows remote code execution and denial of service.
The severity of CVE-2011-1517 is critical with a CVSS score of 9.8.
CVE-2011-1517 affects SAP NetWeaver 7.0 by allowing remote code execution and causing denial of service through an error in the DiagTraceHex() function.
An attacker can exploit CVE-2011-1517 by sending a specially-crafted packet to the affected SAP NetWeaver 7.0 system.
Yes, you can refer to the following sources for more information about CVE-2011-1517: http://archives.neohapsis.com/archives/bugtraq/2012-05/0061.html, https://exchange.xforce.ibmcloud.com/vulnerabilities/75452, http://www.securityfocus.com/bid/53424