VYPR
Unrated severityNVD Advisory· Published Apr 15, 2004· Updated Apr 16, 2026

CVE-2003-1035

CVE-2003-1035

Description

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.

Affected products

3
  • SAP/Sapgui2 versions
    cpe:2.3:a:sap:sapgui:4.6c:*:windows:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:sapgui:4.6c:*:windows:*:*:*:*:*
    • cpe:2.3:a:sap:sapgui:4.6d:*:windows:*:*:*:*:*
  • cpe:2.3:a:sap:sap_r_3:*:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.