The Telnet interface in the SAP J2EE Engine Core (SAP-JEECOR) 6.40 through 7.02, and Server Core (SERVERCORE) 7.10 through 7.30 allows remote authenticated users to bypass a security check and conduct SMB relay attacks via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2010-005 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/59502 | vdb entry |
http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0371.html | mailing list |
https://service.sap.com/sap/support/notes/1425847 | |
http://www.securityfocus.com/archive/1/511855/100/0/threaded | mailing list |
http://secunia.com/advisories/40223 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/40916 | vdb entry |
http://www.securitytracker.com/id?1024114 | vdb entry |