First published: Wed Jun 24 2015(Updated: )
The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors, aka SAP Security Notes 2059659 and 2057982.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5067 has a medium severity rating due to the use of hardcoded credentials in SAP NetWeaver.
To mitigate CVE-2015-5067, update your SAP NetWeaver installation with the appropriate security patches provided in SAP Security Notes 2059659 and 2057982.
CVE-2015-5067 allows remote attackers to access SAP NetWeaver systems using hardcoded credentials.
CVE-2015-5067 affects all versions of SAP NetWeaver that utilize the Cross-System Tools and Data Transfer Workbench functionalities.
As of the latest reports, there have been no confirmed active exploitation cases of CVE-2015-5067.