Vulnerability Description
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Gui For Windows | 7.20 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96872Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038122
- https://erpscan.io/advisories/erpscan-17-011-sap-gui-versions-remote-code-execut
- http://www.securityfocus.com/bid/96872Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038122
- https://erpscan.io/advisories/erpscan-17-011-sap-gui-versions-remote-code-execut
FAQ
What is CVE-2017-6950?
CVE-2017-6950 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
How severe is CVE-2017-6950?
CVE-2017-6950 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-6950?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Gui For Windows.