An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and write to arbitrary files via unknown vectors.Referenceshttp://archives.neohapsis.com/archives/bugtraq/2013-02/0133.htmlhttps://service.sap.com/sap/support/notes/1682613http://scn.sap.com/docs/DOC-8218http://www.onapsis.com/get.php?resid=adv_onapsis-2013-004http://www.onapsis.com/research-advisories.php