Description
An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.
CVSS breakdown
Affected products
- SAP_SE / SAP Web DispatcherWEBDISP 7.49 – WEBDISP 7.49
- SAP_SE / SAP Web DispatcherWEBDISP 7.53 – WEBDISP 7.53
- SAP_SE / SAP Web DispatcherWEBDISP 7.54 – WEBDISP 7.54
- SAP_SE / SAP Web DispatcherWEBDISP 7.77 – WEBDISP 7.77
- SAP_SE / SAP Web DispatcherWEBDISP 7.81 – WEBDISP 7.81
- SAP_SE / SAP Web DispatcherWEBDISP 7.85 – WEBDISP 7.85
- SAP_SE / SAP Web DispatcherWEBDISP 7.88 – WEBDISP 7.88
- SAP_SE / SAP Web DispatcherWEBDISP 7.89 – WEBDISP 7.89
- SAP_SE / SAP Web DispatcherWEBDISP 7.90 – WEBDISP 7.90
- SAP_SE / SAP Web DispatcherKERNEL 7.49 – KERNEL 7.49
- SAP_SE / SAP Web DispatcherKERNEL 7.53 – KERNEL 7.53
- SAP_SE / SAP Web DispatcherKERNEL 7.54 KERNEL 7.77 – KERNEL 7.54 KERNEL 7.77
- SAP_SE / SAP Web DispatcherKERNEL 7.81 – KERNEL 7.81
- SAP_SE / SAP Web DispatcherKERNEL 7.85 – KERNEL 7.85
- SAP_SE / SAP Web DispatcherKERNEL 7.88 – KERNEL 7.88
- SAP_SE / SAP Web DispatcherKERNEL 7.89 – KERNEL 7.89
- SAP_SE / SAP Web DispatcherKERNEL 7.90 – KERNEL 7.90
- SAP_SE / SAP Web DispatcherKRNL64NUC 7.49 – KRNL64NUC 7.49
- SAP_SE / SAP Web DispatcherKRNL64UC 7.49 – KRNL64UC 7.49
- SAP_SE / SAP Web DispatcherKRNL64UC 7.53 – KRNL64UC 7.53
- SAP_SE / SAP Web DispatcherHDB 2.00 – HDB 2.00
- SAP_SE / SAP Web DispatcherXS_ADVANCED_RUNTIME 1.00 – XS_ADVANCED_RUNTIME 1.00
- SAP_SE / SAP Web DispatcherSAP_EXTENDED_APP_SERVICES 1 – SAP_EXTENDED_APP_SERVICES 1