PT-2016-7329 · Sap · Sap Netweaver

Pablo Artuso

·

Published

2016-10-05

·

Updated

2016-11-28

·

CVE-2016-7435

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Netweaver version 7.40 SP 12
Description The issue allows remote authenticated users with certain permissions to execute arbitrary commands. This is achieved through vectors involving a CALL 'SYSTEM' statement in the SCTC subpackage, specifically in the (1) SCTC REFRESH EXPORT TAB COMP, (2) SCTC REFRESH CHECK ENV, and (3) SCTC TMS MAINTAIN ALOG functions.
Recommendations For SAP Netweaver version 7.40 SP 12, consider restricting access to the SCTC subpackage functions, specifically SCTC REFRESH EXPORT TAB COMP, SCTC REFRESH CHECK ENV, and SCTC TMS MAINTAIN ALOG, to minimize the risk of exploitation. As a temporary workaround, consider disabling the CALL 'SYSTEM' statement in these functions until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7435

Affected Products

Sap Netweaver