SAP Message Server HTTP Request Handling Remote Buffer Overflow Vulnerability
Description
A vulnerability has been identified in SAP Message Server, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by a buffer overflow error when processing overly long HTTP requests, which could be exploited by attackers to crash or compromise a vulnerable server e.g. by supplying an overly long "group" parameter to the "msgserver/html/group" script.
Vulnerable Products
Vulnerable Software: SAP Message Server
Solution
Upgrade to the latest version :ftp://ftp.sap.com/pub