CVE-2013-1592

Description

A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
68.888

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 7.01Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 7.02Windows
Vulnerabilities CVE-2013-1592,CVE-2013-1593,CVE-2016-4551 are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 2004sWindows
Vulnerabilities CVE-2013-1592,CVE-2013-1593 are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 7.30Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP Platform (Service Data Collection) 7.30Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234