CVE-2003-0747 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~language, (4) ~theme, or (5) ~template, which leaks the information in the resulting error message.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.15% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-10-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | internet transaction server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Information Disclosure | 2003-08-30 |
References
- http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html
- http://www.securityfocus.com/bid/8515
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13063
- http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html
- http://www.securityfocus.com/bid/8515
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13063
→ the Explorer · watch your stack · NVD