By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netweaver | Sap | 7.22ext (including) | 7.22ext (including) |
Netweaver | Sap | 7.49 (including) | 7.49 (including) |
Netweaver | Sap | 7.53 (including) | 7.53 (including) |
Netweaver | Sap | 7.77 (including) | 7.77 (including) |
Netweaver | Sap | 7.81 (including) | 7.81 (including) |
Netweaver | Sap | 7.85 (including) | 7.85 (including) |
Netweaver | Sap | 7.86 (including) | 7.86 (including) |
Netweaver | Sap | kernel_7.22 (including) | kernel_7.22 (including) |
Netweaver | Sap | krnl64nuc_7.22 (including) | krnl64nuc_7.22 (including) |
Netweaver | Sap | krnl64uc_7.22 (including) | krnl64uc_7.22 (including) |
Web_dispatcher | Sap | 7.53 (including) | 7.53 (including) |
Web_dispatcher | Sap | 7.77 (including) | 7.77 (including) |
Web_dispatcher | Sap | 7.81 (including) | 7.81 (including) |
Web_dispatcher | Sap | 7.85 (including) | 7.85 (including) |
Web_dispatcher | Sap | 7.86 (including) | 7.86 (including) |