Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2017-16682 Code Injection vulnerability in SAP NetWeaver/ITS, SAP security note 2526781

SAP Note 2526781

SAP security note 2526781, "[CVE-2017-16682] Code Injection Vulnerability in SAP NetWeaver/ITS". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP ITS allows an attacker with administrator credentials to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Some well-known impacts of Code Injection vulnerability are:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

Please apply the Basis Support Package associated with this note or implement the attached correction instruction.

Reason and prerequisites

Prerequisite: Edit right for Service Configuration in transaction SICF. Ensure the following SAP Notes are applied based on your SAP_BASIS version: for versions 700 to 740, SAP Note 2242128; for versions 750 to 752, SAP Note 2474240.

CVSS

Score 5.1 / 10 Vector: AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

Affected components

  • SAP_BASIS versions 700 to 752

Full note on SAP: SAP Support Launchpad note 2526781

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More