CVE-2013-3244
SAP ERP Central Component - Remote Code Execution via CJDB_FILL_MEMORY_FROM_PPB Function
Title source: manualDescription
Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (ECC) allow remote attackers to execute arbitrary code via a (1) RFC or (2) SOAP-RFC request.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
http://scn.sap.com/docs/DOC-8218
Various Sources x_refsource_misc
https://service.sap.com/sap/support/notes/1776695
Various Sources x_refsource_misc
http://www.esnc.de/sap-security-audit-and-scan-services/security-advisories/58-remote-code-injection-in-sap-erp-project-system.html
Scores
EPSS
0.0112
EPSS Percentile
78.5%
Details
CWE
CWE-94
Status
published
Products (1)
sap/erp_central_component
Published
Oct 24, 2013
Tracked Since
Feb 18, 2026