CVE-2016-7435
Last modified
CVE-2016-7435 is a vulnerability of currently unknown severity. The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.. EPSS estimates a 3.34% chance of exploitation in the next 30 days.
Description
The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sap | Netweaver | 7.40 | Sp12 |
References
- http://seclists.org/fulldisclosure/2016/Oct/0Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/1Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/2Mailing List, Third Party Advisory
- https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/0Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/1Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/2Mailing List, Third Party Advisory
- https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7435?
How severe is CVE-2016-7435?
How do I fix CVE-2016-7435?
Are you affected by CVE-2016-7435?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
