PT-2017-14521 · Sap · Sap Netweaver Internet Transaction Server

Published

2017-12-12

·

Updated

2017-12-22

·

CVE-2017-16682

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Internet Transaction Server (ITS) versions 7.00 through 7.02 SAP NetWeaver Internet Transaction Server (ITS) version 7.30 SAP NetWeaver Internet Transaction Server (ITS) version 7.31 SAP NetWeaver Internet Transaction Server (ITS) version 7.40 SAP NetWeaver Internet Transaction Server (ITS) versions 7.50 through 7.52
Description The issue allows an attacker with administrator credentials to inject code that can be executed by the application, thereby controlling the behavior of the application.
Recommendations For SAP NetWeaver Internet Transaction Server (ITS) versions 7.00 through 7.02, update to a version outside of this range to mitigate the risk. For SAP NetWeaver Internet Transaction Server (ITS) version 7.30, update to a version outside of this range to mitigate the risk. For SAP NetWeaver Internet Transaction Server (ITS) version 7.31, update to a version outside of this range to mitigate the risk. For SAP NetWeaver Internet Transaction Server (ITS) version 7.40, update to a version outside of this range to mitigate the risk. For SAP NetWeaver Internet Transaction Server (ITS) versions 7.50 through 7.52, update to a version outside of this range to mitigate the risk.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16682

Affected Products

Sap Netweaver Internet Transaction Server