CVE-2017-16691
Summary
| CVE | CVE-2017-16691 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-12 14:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file contained in the SAR archive. It is possible to append a tampered file to the SAR archive using SAPCAR tool and during the extraction, digital signature verification fails but the tampered file is extracted. |
Risk And Classification
Primary CVSS: v3.0 6.5 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS: 0.003690000 probability, percentile 0.588810000 (date 2026-05-18)
Problem Types: CWE-20 | Digital signature verification along with note file extraction
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 5.8 | AV:N/AC:M/Au:N/C:N/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Business Application Software Integrated Solution | 7.00 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.01 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.02 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.10 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.11 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.30 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.31 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.40 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.50 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.51 | All | All | All |
| Application | Sap | Business Application Software Integrated Solution | 7.52 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP | SAP Note Assistant | affected SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – December 2017 | SAP Blogs | af854a3a-2127-422b-91ae-364da2661108 | blogs.sap.com | Issue Tracking, Vendor Advisory |
| launchpad.support.sap.com | af854a3a-2127-422b-91ae-364da2661108 | launchpad.support.sap.com | Permissions Required, Vendor Advisory |
| SAP NOTE Unspecified Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.