CVE-2017-16682
Summary
| CVE | CVE-2017-16682 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-12 14:29:00 UTC |
| Updated | 2017-12-22 14:34:00 UTC |
| Description | SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Business Application Software Integrated Solution | 7.30 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.31 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.40 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.30 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.31 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.40 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | All | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | All | All | All | All |
| Application | Sap | Netweaver Internet Transaction Server | - | All | All | All |
| Application | Sap | Netweaver Internet Transaction Server | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – December 2017 | SAP Blogs | CONFIRM | blogs.sap.com | Vendor Advisory |
| SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| launchpad.support.sap.com | CONFIRM | launchpad.support.sap.com | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.