Vulnerability Name: | CCN-71312 | ||||||
Published: | 2011-11-11 | ||||||
Updated: | 2011-11-11 | ||||||
Summary: | SAP Netweaver could allow a remote attacker to execute arbitrary code on the system, caused by an error in the CTC service when performing certain authentication checks. An attacker could exploit this vulnerability using the Verb Tampering issue to gain unauthorized access to user management and OS command execution functionality to execute arbitrary code on the system. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: DSECRG-041 SAP NetWeaver - Authentication bypass (Verb Tampering) Source: CCN Type: SA46852 SAP NetWeaver Multiple Vulnerabilities Source: CCN Type: BID-50680 SAP Netweaver Multiple Security Vulnerabilities Source: XF Type: UNKNOWN netweaver-ctc-code-execution(71312) Source: CCN Type: SAP Web site SAP Security Note 1624450 | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |