CVE-2005-4815

UnknownEPSS 2.58%

Last modified

CVE-2005-4815 is a vulnerability of currently unknown severity. SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln.". EPSS estimates a 2.58% chance of exploitation in the next 30 days.

Description

SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."

Metrics

EPSS Probability
2.58%

83.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
SapSap R 34.6_before_patch_1767
SapSap R 36.2_before_patch_1364
SapSap R 36.4_before_patch_4
SapSap R 331_before_31i_patch_735
SapSap R 340_before_patch_1008
SapSap R 345_before_patch_913

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-4815?
SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."
How severe is CVE-2005-4815?
Severity scoring for CVE-2005-4815 is pending analysis. The EPSS model estimates a 2.58% probability of exploitation in the next 30 days.
How do I fix CVE-2005-4815?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-4815?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST