Description
SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."
References (5)
Core 5
Core References
Various Sources mailing-list
x_refsource_mlist
http://lists.virus.org/darklab-0509/msg00017.html
Various Sources mailing-list
x_refsource_mlist
http://lists.virus.org/darklab-0509/msg00011.html
Various Sources mailing-list
x_refsource_mlist
http://lists.darklab.org/pipermail/darklab/2006-January/000209.html
Various Sources mailing-list
x_refsource_mlist
http://lists.virus.org/darklab-0509/msg00018.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451378/100/0/threaded
Scores
EPSS
0.0231
EPSS Percentile
85.0%
Details
Status
published
Products (6)
sap/sap_r_3
4.6_before_patch_1767
sap/sap_r_3
6.2_before_patch_1364
sap/sap_r_3
6.4_before_patch_4
sap/sap_r_3
31_before_31i_patch_735
sap/sap_r_3
40_before_patch_1008
sap/sap_r_3
45_before_patch_913
Published
Dec 31, 2005
Tracked Since
Feb 18, 2026