VulnerabilityModified
CVE-2016-6147
An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226.
CRITICAL 9.8EPSS 4.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.54% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- sap/trex
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/138446/SAP-TREX-7.10-Revision-63-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2016/Aug/94
- http://www.securityfocus.com/bid/92066Third Party Advisory, VDB Entry
- https://www.onapsis.com/blog/analyzing-sap-security-notes-february-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-trex-remote-command-execution-0Permissions Required
- http://packetstormsecurity.com/files/138446/SAP-TREX-7.10-Revision-63-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2016/Aug/94
- http://www.securityfocus.com/bid/92066Third Party Advisory, VDB Entry
- https://www.onapsis.com/blog/analyzing-sap-security-notes-february-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-trex-remote-command-execution-0Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.