← Back

CVE-2014-0984

nvd nist
Published: Apr 17, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain passwords via a brute-force attack that relies on timing differences in responses to incorrect password guesses, aka a timing side-channel attack.

Affected (3)

Products: Sap: Router
1 product
Router
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 710 029
Version 720 411
Version 721 117

Related CWEs

References (10)

Timeline

No history available yet.