>> SAP Message Server HTTP Request Handling Remote Buffer Overflow Vulnerability
Title : SAP Message Server HTTP Request Handling Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2451 CVE ID : CVE-2007-3624
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-06
Technical Description
A vulnerability has been identified in SAP Message Server, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error when processing overly long HTTP requests, which could be exploited by attackers to crash or compromise a vulnerable server e.g. by supplying an overly long "group" parameter to the "msgserver/html/group" script.