CVE-2012-4341

critical
Published 2012-08-15 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Multiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) long parameter value, (2) crafted string size field, or (3) long Parameter Name string in a package with opcode 0x43 and sub opcode 0x4 to TCP port 3900.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/49744

Application impact

VendorProductVersionsFixed
sapnetweaver_abap7.0
sapnetweaver_abap7.02
sapnetweaver_abap7.03

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.