The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote malicious users to execute arbitrary code via a crafted SAP Diag packet.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sap netweaver 7.0 |