CVE-2005-4815
Last modified
CVE-2005-4815 is a vulnerability of currently unknown severity. SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln.". EPSS estimates a 2.58% chance of exploitation in the next 30 days.
Description
SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap R 3 | 4.6_before_patch_1767 |
| Sap | Sap R 3 | 6.2_before_patch_1364 |
| Sap | Sap R 3 | 6.4_before_patch_4 |
| Sap | Sap R 3 | 31_before_31i_patch_735 |
| Sap | Sap R 3 | 40_before_patch_1008 |
| Sap | Sap R 3 | 45_before_patch_913 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4815?
How severe is CVE-2005-4815?
How do I fix CVE-2005-4815?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-4809Mozilla Firefox 1.0.1 and possibly other versions, including…
- CVE-2005-4810Microsoft Internet Explorer 7.0 Beta3 and earlier allows rem…
- CVE-2005-4811The hugepage code (hugetlb.c) in Linux kernel 2.6, possibly …
- CVE-2005-4812The SISCO OSI stack for Windows, as used by MMS-EASE 7.10 an…
- CVE-2005-4813Unspecified vulnerability in Report Application Server (Crys…
- CVE-2005-4814Unrestricted file upload vulnerability in Segue CMS before 1…
- CVE-2005-4816Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 all…
- CVE-2005-4817Format string vulnerability in ui.c in Textbased MSN Client …
- CVE-2005-4818Multiple SQL injection vulnerabilities in Copernicus Europa …
- CVE-2005-4819Cross-site scripting (XSS) vulnerability in Lotus Domino ver…
- CVE-2005-4820SMC Wireless Router model SMC7904WBRA allows remote attacker…
- CVE-2005-4821Multiple SQL injection vulnerabilities in Land Down Under (L…
Are you affected by CVE-2005-4815?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
