SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

SAP RFC_START_PROGRAM RFC Function Multiple Vulnerabilities


Arrow  SecurityAlert : 2538
Arrow  CVE : CVE-2007-1915
Arrow  CVE : CVE-2007-1914
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : Mariano Nuez Di Croce
Arrow  Published : 11.04.2007

Arrow  Affected Software : SAP, RFC Library, 6.4
SAP, RFC Library, 7.0
Running on IBM, AIX
Running on HP, HP-UX
═ Running on Linux, Linux, IA32 64-bit
═ Running on Apple, Mac OS
═ Running on IBM, OS/400, Gold
═ Running on IBM, OS/400, V5R2M0
═ Running on Siemens, Reliant UNIX
═ Running on Sun, Solaris
═ Running on HP, Tru64
═ Running on IBM, ZOS
═ Running on Microsoft, Windows Server



Arrow  Advisory Content :  

(The following pre-advisory is also available in PDF format for download
at:
http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRA
M_RFC_Function_Multiple_Vulnerabilities.pdf )

CYBSEC S.A.
www.cybsec.com

Pre-Advisory Name: SAP RFC_START_PROGRAM RFC Function Multiple
Vulnerabilities
==================

Vulnerability Class: Buffer Overflow, Information Disclosure
====================

Release Date: 2007-04-03
=============

Affected Applications:
======================
. SAP RFC Library 6.40
. SAP RFC Library 7.00

Affected Platforms:
===================

. AIX 32bit
. AIX 64bit
. HP-UX on IA64 64bit
. HP-UX on PA-RISC 64bit
. Linux on IA32 32bit
. Linux on IA64 64bit
. Linux on Power 64bit
. Linux on x86_64 64bit
. Linux on zSeries 64bit
. Mac OS
. OS/400
. OS/400 V5R2M0
. Reliant 32bit
. Solaris on SPARC 32bit
. Solaris on SPARC 64bit
. Solaris on x64_64 64bit
. TRU64 64bit
. Windows Server on IA32 32bit
. Windows Server on IA64 64bit
. Windows Server on x64 64bit
. z/OS 32bit

Local / Remote: Remote
===============

Severity: High
=========

Author: Mariano Nuñez Di Croce
=======

Vendor Status: Confirmed. Updates Released.
==============

Reference to Vulnerability Disclosure Policy:
http://www.cybsec.com/vulnerability_policy.pdf
=============================================

Product Overview:
=================

"The RFC Library offers an interface to a SAP System. The RFC Library is
the most commonly used and installed component of existing SAP Software.
This
interface provides the opportunity to call any RFC Function in a SAP System
from an external application. Moreover, the RFC Library offers the
possibility to write a RFC Server Program, which is accessible from any SAP
System or external application. Most SAP Connectors use the RFC Library as
communication platform to SAP Systems."

RFC_START_PROGRAM RFC Function enables the execution of operating system
programs on RFC-enabled components. This function is installed by default
in
every external RFC server.

Vulnerability Description:
==========================

It is possible to remotely obtain information about external RFC server
configuration. Besides, a buffer overflow vulnerability in the processing
of
user input has been detected.

Technical Details:
==================

Technical details will be released three months after publication of this
pre-advisory. This was agreed upon with SAP to allow their customers to
upgrade affected software prior to technical knowledge been publicly
available.

Impact:
=======

These vulnerabilities may allow an attacker to remotely obtain information
about RFC server configuration and to remotely execute arbitrary commands
over vulnerable external RFC servers.

Solutions:
==========

SAP has released patches to address these vulnerabilities. Affected
customers should apply the patches immediately.
More information can be found on SAP Notes 1004084 and 1003908.

Vendor Response:
================

. 2006-11-21: Initial Vendor Contact.
. 2006-12-01: Vendor Confirmed Vulnerability.
. 2006-12-11: Vendor Releases Update for version 6.40.
. 2006-12-11: Vendor Releases Update for version 7.00.
. 2007-04-03: Pre-Advisory Public Disclosure.

Special Thanks:
===============

Thanks goes to Victor Montero and Gustavo Kunst.

Contact Information:
====================
For more information regarding the vulnerability feel free to contact the
author at mnunez <at> cybsec <dot> com.

About CYBSEC S.A. Security Systems
-----------------------------------

Since 1996 CYBSEC S.A. is devoted exclusively to provide professional
services specialized in Computer Security. More than 150 clients around
the
globe validate our quality and professionalism.
To keep objectivity, CYBSEC S.A. does not represent, neither sell, nor is
associated with other software and/or hardware provider companies.
Our services are strictly focused on Information Security, protecting our
clients from emerging security threats, mantaining their IT deployments
available, safe, and reliable.
Beyond professional services, CYBSEC is continuosly researching new defense
and attack techiniques and contributing with the security community with
high quality information exchange.

For more information, please visit www.cybsec.com

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD4DBQFGE54JvWPewvmdrSgRAjsUAJ48fQbAyfLtFbQ4azH5oHsIASgc5wCVFEz9
CRbmY1qe9uUsGA848XNxKA==
=dbdW
-----END PGP SIGNATURE-----





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.