SAP security note 2526781, "[CVE-2017-16682] Code Injection Vulnerability in SAP NetWeaver/ITS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP ITS allows an attacker with administrator credentials to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Some well-known impacts of Code Injection vulnerability are:
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
Please apply the Basis Support Package associated with this note or implement the attached correction instruction.
Reason and prerequisites
Prerequisite: Edit right for Service Configuration in transaction SICF. Ensure the following SAP Notes are applied based on your SAP_BASIS version: for versions 700 to 740, SAP Note 2242128; for versions 750 to 752, SAP Note 2474240.
CVSS
Score 5.1 / 10 Vector: AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
Affected components
- SAP_BASIS versions 700 to 752
Full note on SAP: SAP Support Launchpad note 2526781
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
