First published: Wed Apr 30 2014(Updated: )
The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server for ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3130 has a moderate severity level as it allows local users to gain privileges if exploited.
To remediate CVE-2014-3130, ensure that proper access restrictions are applied to the ABAP Help documentation and translation tools.
CVE-2014-3130 affects users of SAP NetWeaver ABAP Application Server with insufficient access controls.
CVE-2014-3130 is an access control vulnerability due to improper restrictions in the documentation tools.
Yes, CVE-2014-3130 can allow local users to execute ABAP instructions, potentially leading to further exploitation.