CVE-2016-7435
The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.34% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sap/netweaver
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2016/Oct/0Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/1Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/93272
- https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctcrefreshcheckenvThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctcrefreshexporttabcompThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctctmsmaintainalogThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/0Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/1Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/93272
- https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctcrefreshcheckenvThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctcrefreshexporttabcompThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctctmsmaintainalogThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.