CVE-2016-3635
Last modified
CVE-2016-3635 is a vulnerability of currently unknown severity. SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver | 7.40 |
References
- http://seclists.org/fulldisclosure/2016/Oct/48Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/48Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3635?
How severe is CVE-2016-3635?
How do I fix CVE-2016-3635?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-3629Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-3630The binary delta decoder in Mercurial before 3.7.3 allows re…8.8
- CVE-2016-3631The (1) cpStrips and (2) cpTiles functions in the thumbnail …
- CVE-2016-3632The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.…
- CVE-2016-3633The setrow function in the thumbnail tool in LibTIFF 4.0.6 a…
- CVE-2016-3634The tagCompare function in tif_dirinfo.c in the thumbnail to…
- CVE-2016-3638SAP SLD Registration Program (aka SLDREG) allows local users…
- CVE-2016-3639SAP HANA DB 1.00.091.00.1418659308 allows remote attackers t…
- CVE-2016-3640The Extended Application Services (aka XS or XS Engine) in S…
- CVE-2016-3642The RMI service in SolarWinds Virtualization Manager 6.3.1 a…
- CVE-2016-3643SolarWinds Virtualization Manager 6.3.1 and earlier allow lo…7.8
- CVE-2016-3644The AntiVirus Decomposer engine in Symantec Advanced Threat …
Are you affected by CVE-2016-3635?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
