MEDIUM · 5.0

CVE-2007-1918

The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denia...

Vulnerability Description

The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmRacf-
AppleMacosAll versions
HpHp-UxAll versions
HpTru64All versions
IbmAixAll versions
IbmOs 400All versions
LinuxLinux KernelAll versions
MicrosoftWindows ServerAll versions
SiemensReliant UnixAll versions
SunSolarisAll versions
SapRfc Library6.4

References

FAQ

What is CVE-2007-1918?

CVE-2007-1918 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denia...

How severe is CVE-2007-1918?

CVE-2007-1918 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1918?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Racf, Apple Macos, Hp Hp-Ux, Hp Tru64, Ibm Aix.