CVE-2012-2612: Buffer Overflow
Published May 15, 2012
·Updated
The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
Affected Software
2 affected components
SAP NetWeaver=7.0-ehp1
SAP NetWeaver=7.0-ehp2
Event History
May 15, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2612?
CVE-2012-2612 has a medium severity rating due to its potential to cause a denial of service in SAP NetWeaver.
2
How do I fix CVE-2012-2612?
To fix CVE-2012-2612, it is recommended to update to the latest version of SAP NetWeaver that addresses this vulnerability.
3
Which SAP NetWeaver versions are affected by CVE-2012-2612?
CVE-2012-2612 affects SAP NetWeaver versions 7.0 EHP1 and EHP2.
4
What type of attack does CVE-2012-2612 allow?
CVE-2012-2612 allows remote attackers to perform denial of service attacks by exploiting the DiagTraceHex function.
5
What component of SAP is involved in CVE-2012-2612?
CVE-2012-2612 involves the Dispatcher in SAP NetWeaver which is susceptible to crafted SAP Diag packets.