ID

VAR-201010-0440


TITLE

SAP Management Console Null Pointer Reference Denial of Service Vulnerability

Trust: 0.8

sources: IVD: 35193aea-1fad-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2177

DESCRIPTION

The SAP Management Console is a management console for SAP products. A security vulnerability exists in the SAP Management Console that allows an attacker to exploit this vulnerability to trigger a null pointer application, destroy the primary management interface, and perform a denial of service attack. Due to the nature of this issue, arbitrary code execution may be possible; this has not been confirmed

Trust: 0.99

sources: CNVD: CNVD-2010-2177 // BID: 43548 // IVD: 35193aea-1fad-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 35193aea-1fad-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2177

AFFECTED PRODUCTS

vendor:sapmodel:management consolescope:eqversion:6.40

Trust: 0.8

vendor:sapmodel:management consolescope:eqversion:7.10

Trust: 0.6

vendor:sapmodel:management consolescope:eqversion:7.00

Trust: 0.6

vendor:sapmodel:management consolescope:eqversion:7.10*

Trust: 0.2

vendor:sapmodel:management consolescope:eqversion:7.00*

Trust: 0.2

sources: IVD: 35193aea-1fad-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2177

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 35193aea-1fad-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 35193aea-1fad-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 35193aea-1fad-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 43548

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 43548

PATCH

title:SAP Management Console null pointer reference patch for denial of service vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/1167

Trust: 0.6

sources: CNVD: CNVD-2010-2177

EXTERNAL IDS

db:BIDid:43548

Trust: 0.9

db:CNVDid:CNVD-2010-2177

Trust: 0.8

db:IVDid:35193AEA-1FAD-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 35193aea-1fad-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2177 // BID: 43548

REFERENCES

url:http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2010-007

Trust: 0.9

url:http://www.sap.com/

Trust: 0.3

url:https://service.sap.com/sap/support/notes/1151410

Trust: 0.3

url:https://service.sap.com/sap/support/notes/1469804

Trust: 0.3

sources: CNVD: CNVD-2010-2177 // BID: 43548

CREDITS

Jordan Santarsieri from Onapsis

Trust: 0.3

sources: BID: 43548

SOURCES

db:IVDid:35193aea-1fad-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2010-2177
db:BIDid:43548

LAST UPDATE DATE

2022-05-17T02:08:19.708000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-2177date:2010-10-08T00:00:00
db:BIDid:43548date:2010-09-27T00:00:00

SOURCES RELEASE DATE

db:IVDid:35193aea-1fad-11e6-abef-000c29c66e3ddate:2010-10-08T00:00:00
db:CNVDid:CNVD-2010-2177date:2010-10-08T00:00:00
db:BIDid:43548date:2010-09-27T00:00:00