CVE-2017-7717
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sap/netweaver application server java
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/100168Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95364Third Party Advisory, VDB Entry
- https://erpscan.io/advisories/erpscan-17-003-sap-netweaver-7-4-getuseruddielements-sql-injection/Third Party Advisory
- http://www.securityfocus.com/bid/100168Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95364Third Party Advisory, VDB Entry
- https://erpscan.io/advisories/erpscan-17-003-sap-netweaver-7-4-getuseruddielements-sql-injection/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.