The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.
Score: 3.25
Priority: P2 - Serious (High)
Score: 0.00363
Percentile:
0.57588
CVSS v2 Score: 7.5
Severity: