PT-2016-7329 · Sap · Sap Netweaver
Pablo Artuso
·
Publicado
2016-10-05
·
Atualizado
2016-11-28
·
CVE-2016-7435
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Netweaver version 7.40 SP 12
Description
The issue allows remote authenticated users with certain permissions to execute arbitrary commands. This is achieved through vectors involving a CALL 'SYSTEM' statement in the SCTC subpackage, specifically in the (1) SCTC REFRESH EXPORT TAB COMP, (2) SCTC REFRESH CHECK ENV, and (3) SCTC TMS MAINTAIN ALOG functions.
Recommendations
For SAP Netweaver version 7.40 SP 12, consider restricting access to the SCTC subpackage functions, specifically SCTC REFRESH EXPORT TAB COMP, SCTC REFRESH CHECK ENV, and SCTC TMS MAINTAIN ALOG, to minimize the risk of exploitation. As a temporary workaround, consider disabling the CALL 'SYSTEM' statement in these functions until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver