PT-2024-3897 · Sap · Sap Ides Ecc-Systems

Published

2024-02-12

·

Updated

2024-10-16

·

CVE-2024-22132

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: SAP IDES ECC-systems (affected versions not specified)
Description: The issue allows the execution of arbitrary program code of a user's choice, potentially enabling an attacker to control the system's behavior by executing malicious code. This could escalate privileges, although with low impact on confidentiality, integrity, and availability of the system. The vulnerability exists due to the lack of measures to neutralize special elements used in the operating system command.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-04304
CVE-2024-22132

Affected Products

Sap Ides Ecc-Systems