CVE-2013-7364

SAP NetWeaver - Unauthenticated Arbitrary File Read and Write

Title source: llm
STIX 2.1

Description

An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and write to arbitrary files via unknown vectors.

References (5)

Core 5
Core References
Various Sources x_refsource_confirm
http://scn.sap.com/docs/DOC-8218
Various Sources x_refsource_misc
http://www.onapsis.com/research-advisories.php
Various Sources x_refsource_misc
https://service.sap.com/sap/support/notes/1682613
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-02/0133.html

Scores

EPSS 0.0067
EPSS Percentile 71.7%

Details

CWE
CWE-264
Status published
Products (1)
sap/netweaver
Published Apr 10, 2014
Tracked Since Feb 18, 2026