----------------------------------------------------------------------

To improve our services to our customers, we have made a number of
additions to the Secunia Advisories and have started translating the
advisories to German.

The improvements will help our customers to get a better
understanding of how we reached our conclusions, how it was rated,
our thoughts on exploitation, attack vectors, and scenarios.

This includes:
* Reason for rating
* Extended description
* Extended solution
* Exploit code or links to exploit code
* Deep links

Read the full description:
http://corporate.secunia.com/products/48/?r=l

Contact Secunia Sales for more information:
http://corporate.secunia.com/how_to_buy/15/?r=l

----------------------------------------------------------------------

TITLE:
SAP Web Application Server Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA22677

VERIFY ADVISORY:
http://secunia.com/advisories/22677/

CRITICAL:
Moderately critical

IMPACT:
Exposure of sensitive information, DoS

WHERE:
>From remote

SOFTWARE:
SAP Web Application Server 7.x
http://secunia.com/product/6087/
SAP Web Application Server 6.x
http://secunia.com/product/3327/

DESCRIPTION:
Nicob has reported some vulnerabilities in SAP Web Application
Server, which can be exploited by malicious people to disclose
sensitive information or to cause a DoS (Denial of Service).

1) Due to an unspecified error it is possible to read arbitrary files
on the system with privileges of the web server. 

2) An unspecified error allows crashing the enserver.exe process.

The vulnerabilities are reported in version 6.40 and 7.00. Other
versions may also be affected.

SOLUTION:
Apply patch.

SAP Web Application Server 6.40:
Install patch 136.

SAP Web Application Server 7.00:
Install patch 66.

PROVIDED AND/OR DISCOVERED BY:
Nicob

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

----------------------------------------------------------------------