CVE-2024-22127
Last modified
CVE-2024-22127 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.. EPSS estimates a 1.59% chance of exploitation in the next 30 days.
Description
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.5 |
References
- https://me.sap.com/notes/3433192Permissions Required
- https://me.sap.com/notes/3433192Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-22127?
How severe is CVE-2024-22127?
How do I fix CVE-2024-22127?
Are you affected by CVE-2024-22127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
