CVE-2013-3319: Infoleak
Published Aug 16, 2013
·Updated
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.
Affected Software
1 affected component
SAP NetWeaver=7.03
Event History
Aug 16, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3319?
CVE-2013-3319 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-3319?
To fix CVE-2013-3319, update SAP NetWeaver to the latest version that addresses this vulnerability.
3
What type of information can be exposed due to CVE-2013-3319?
CVE-2013-3319 allows attackers to obtain sensitive information from the affected SAP NetWeaver service.
4
What services are affected by CVE-2013-3319?
CVE-2013-3319 affects the GetComputerSystem method in the HostControl service of SAP NetWeaver 7.03.
5
How is CVE-2013-3319 exploited?
CVE-2013-3319 can be exploited by sending a crafted SOAP request to TCP port 1128.