Vulnerability Description
The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver | 7.40 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2016/Oct/0Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/1Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93272
- https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-scThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-scThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-scThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/0Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/1Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2016/Oct/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93272
- https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-scThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-os-command-injection-scThird Party Advisory
FAQ
What is CVE-2016-7435?
CVE-2016-7435 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with cert...
How severe is CVE-2016-7435?
CVE-2016-7435 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-7435?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver.