CVE-2024-22127
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- sap/netweaver application server java
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3433192Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364Vendor Advisory
- https://me.sap.com/notes/3433192Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.