Information Disclosure in SAP RFC Library Versions 6.40 and 7.00
CVE-2007-1914

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 April 2007

What is CVE-2007-1914?

The RFC_START_PROGRAM function in SAP's RFC Library versions 6.40 and 7.00 prior to December 11, 2006, is susceptible to a vulnerability that enables remote attackers to retrieve sensitive information, specifically external RFC server configuration data. This flaw can be exploited through various unspecified vectors, highlighting a significant risk to users of these affected versions. It is essential for organizations utilizing this library to apply the necessary updates and mitigate potential security threats.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.