← Vulnerability feed

Vulnerability record · CVE-2003-1035 · published 15 April 2004

CVE-2003-1035: Sap r 3 vulnerability

Sap · Sap R 3

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.

7.5 CVSS 2.0 High EPSS 1.5% · top 26.0%
7.5CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0620Sapgui memory buffer overflow vulnerabilitySAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LP…EPSS 3.3%9.3CVE-2007-4475Sapgui memory buffer overflow vulnerabilityStack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers t…EPSS 40%9.3CVE-2008-4387Sapgui code injection vulnerabilityUnspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk…EPSS 16%7.5CVE-2008-0621SAP SAPLPD LPD command buffer overflow allows remote code executionSAPLPD 6.28 and earlier, shipped with SAP GUI 7.10 and SAPSprint before 1018, contains a buffer overflow triggered by long arguments to LPD commands …EPSS 73%analysed7.5CVE-2005-4815Sap r 3 vulnerabilitySAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before…EPSS 2.6%7.5CVE-2002-1577Sap r 3 vulnerabilitySAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2…EPSS 1.3%7.5CVE-2002-1578Sap r 3 vulnerabilityThe default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP …EPSS 2.7%5.0CVE-2005-1691Sap r 3 vulnerabilityDirectory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." se…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2003-1035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.