Vulnerability Description
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.40 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100168Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/95364Third Party AdvisoryVDB Entry
- https://erpscan.io/advisories/erpscan-17-003-sap-netweaver-7-4-getuseruddielemenThird Party Advisory
- http://www.securityfocus.com/bid/100168Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/95364Third Party AdvisoryVDB Entry
- https://erpscan.io/advisories/erpscan-17-003-sap-netweaver-7-4-getuseruddielemenThird Party Advisory
FAQ
What is CVE-2017-7717?
CVE-2017-7717 is a vulnerability with a CVSS score of 8.8 (HIGH). SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified ...
How severe is CVE-2017-7717?
CVE-2017-7717 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7717?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Java.