// For flags

CVE-2005-4815

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-12-31 CVE Published
  • 2006-11-21 CVE Reserved
  • 2024-07-27 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Sap R 3
Search vendor "Sap" for product "Sap R 3"
4.6_before_patch_1767
Search vendor "Sap" for product "Sap R 3" and version "4.6_before_patch_1767"
-
Affected
Sap
Search vendor "Sap"
Sap R 3
Search vendor "Sap" for product "Sap R 3"
6.2_before_patch_1364
Search vendor "Sap" for product "Sap R 3" and version "6.2_before_patch_1364"
-
Affected
Sap
Search vendor "Sap"
Sap R 3
Search vendor "Sap" for product "Sap R 3"
6.4_before_patch_4
Search vendor "Sap" for product "Sap R 3" and version "6.4_before_patch_4"
-
Affected
Sap
Search vendor "Sap"
Sap R 3
Search vendor "Sap" for product "Sap R 3"
31_before_31i_patch_735
Search vendor "Sap" for product "Sap R 3" and version "31_before_31i_patch_735"
-
Affected
Sap
Search vendor "Sap"
Sap R 3
Search vendor "Sap" for product "Sap R 3"
40_before_patch_1008
Search vendor "Sap" for product "Sap R 3" and version "40_before_patch_1008"
-
Affected
Sap
Search vendor "Sap"
Sap R 3
Search vendor "Sap" for product "Sap R 3"
45_before_patch_913
Search vendor "Sap" for product "Sap R 3" and version "45_before_patch_913"
-
Affected