Digital Security Research Group [DSecRG] Advisory [DSECRG-10-206] Internal #DSecRG-00125 Application: SAP NetWeaver Versions Affected: SAP NetWeaver 7.0 metamodel repository Vendor URL: http://SAP.com Bugs: Denail of service Exploits: YES Reported: 15.02.2010 Vendor response: 15.02.2010 Date of Public Advisory: 09.11.2010 CVE-number: Author: Alexandr Polyakov from Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com) Description *********** NetWeaver Metamodel Repository affected to denail of service attack by sending a special crafted request. Details ******* http://dsecrg.com/pages/vul/show.php?id=206 References ********** http://dsecrg.com/pages/vul/show.php?id=206 http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a https://service.sap.com/sap/support/notes/1484097 Fix Information *************** Solution for this issue given in security note 1484097. About ***** Digital Security is one of the leading IT security companies in CEMEA, providing information security consulting, audit and penetration testing services, ERP and SAP security assessment, certification for ISO/IEC 27001:2005 and PCI DSS and PA DSS standards. Digital Security Research Group focuses on enterprise application (ERP) and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website. Contact: research [at] dsecrg [dot]com http://www.dsecrg.com http://www.erpscan.com