CVE-2012-2611: Input Validation
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2611?
CVE-2012-2611 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2012-2611?
To fix CVE-2012-2611, apply the latest patches and updates from SAP for affected versions of the NetWeaver software.
Which versions of SAP are affected by CVE-2012-2611?
CVE-2012-2611 affects SAP NetWeaver versions 7.0 EHP1 and EHP2.
What kind of attack is possible with CVE-2012-2611?
CVE-2012-2611 allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.
Is there a workaround for CVE-2012-2611?
As a temporary workaround for CVE-2012-2611, you can disable the Developer Trace configuration in the Dispatcher settings.