CVE-2013-3319

SAP Netweaver 7.03 - Info Disclosure

Title source: llm

Description

The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.

Exploits (2)

nomisec WORKING POC
by devoteam-cybertrust · poc
https://github.com/devoteam-cybertrust/cve-2013-3319
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/sap/sap_hostctrl_getcomputersystem.rb

Scores

EPSS 0.1170
EPSS Percentile 93.7%

Details

CWE
CWE-200
Status published
Products (1)
sap/netweaver 7.03
Published Aug 16, 2013
Tracked Since Feb 18, 2026