{"api_version":"1","generated_at":"2026-07-23T18:56:57+00:00","cve":"CVE-2017-16682","urls":{"html":"https://cve.report/CVE-2017-16682","api":"https://cve.report/api/cve/CVE-2017-16682.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-16682","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-16682"},"summary":{"title":"CVE-2017-16682","description":"SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.","state":"PUBLISHED","assigner":"sap","published_at":"2017-12-12 14:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-94","Code Injection"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/","name":"https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SAP Security Patch Day – December 2017 | SAP Blogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://launchpad.support.sap.com/#/notes/2526781","name":"https://launchpad.support.sap.com/#/notes/2526781","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102143","name":"http://www.securityfocus.com/bid/102143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-16682","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16682","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SAP","product":"SAP NetWeaver Internet Transaction Server (ITS)","version":"affected from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"16682","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"business_application_software_integrated_solution","cpe6":"7.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"16682","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"business_application_software_integrated_solution","cpe6":"7.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"16682","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"business_application_software_integrated_solution","cpe6":"7.40","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"16682","vulnerable":"1","versionEndIncluding":"7.02","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"business_application_software_integrated_solution","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"16682","vulnerable":"1","versionEndIncluding":"7.52","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"business_application_software_integrated_solution","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"16682","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"netweaver_internet_transaction_server","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"16682","cve":"CVE-2017-16682","epss":"0.005460000","percentile":"0.680430000","score_date":"2026-05-17","updated_at":"2026-05-18 00:00:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T20:35:19.953Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"102143","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/102143"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://launchpad.support.sap.com/#/notes/2526781"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"SAP NetWeaver Internet Transaction Server (ITS)","vendor":"SAP","versions":[{"status":"affected","version":"from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52"}]}],"datePublic":"2017-12-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application."}],"problemTypes":[{"descriptions":[{"description":"Code Injection","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-13T10:57:01.000Z","orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap"},"references":[{"name":"102143","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/102143"},{"tags":["x_refsource_CONFIRM"],"url":"https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/"},{"tags":["x_refsource_CONFIRM"],"url":"https://launchpad.support.sap.com/#/notes/2526781"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cna@sap.com","DATE_PUBLIC":"2017-12-12T00:00:00","ID":"CVE-2017-16682","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SAP NetWeaver Internet Transaction Server (ITS)","version":{"version_data":[{"version_value":"from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52"}]}}]},"vendor_name":"SAP"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Code Injection"}]}]},"references":{"reference_data":[{"name":"102143","refsource":"BID","url":"http://www.securityfocus.com/bid/102143"},{"name":"https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/","refsource":"CONFIRM","url":"https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/"},{"name":"https://launchpad.support.sap.com/#/notes/2526781","refsource":"CONFIRM","url":"https://launchpad.support.sap.com/#/notes/2526781"}]}}}},"cveMetadata":{"assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","assignerShortName":"sap","cveId":"CVE-2017-16682","datePublished":"2017-12-12T14:00:00.000Z","dateReserved":"2017-11-09T00:00:00.000Z","dateUpdated":"2024-09-16T22:39:53.093Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-12-12 14:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-94","Code Injection"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:netweaver_internet_transaction_server:-:*:*:*:*:*:*:*","matchCriteriaId":"4EBD79C3-7B56-4065-B2B3-8FC54EB46CF0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*","versionStartIncluding":"7.00","versionEndIncluding":"7.02","matchCriteriaId":"CF38D1E1-E07F-4E51-AE76-E27E7CE4F55C"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*","versionStartIncluding":"7.50","versionEndIncluding":"7.52","matchCriteriaId":"D90BE6E0-559E-4509-95EA-CB820611E16D"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_application_software_integrated_solution:7.30:*:*:*:*:*:*:*","matchCriteriaId":"990D5985-7828-4D8C-9463-CA077AB3881E"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_application_software_integrated_solution:7.31:*:*:*:*:*:*:*","matchCriteriaId":"341C07C1-2B4A-475D-B200-1021EB6B1F79"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_application_software_integrated_solution:7.40:*:*:*:*:*:*:*","matchCriteriaId":"4D80CC30-EE05-439F-BF2C-1267837137DE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"16682","Ordinal":"1","Title":"CVE-2017-16682","CVE":"CVE-2017-16682","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"16682","Ordinal":"1","NoteData":"SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.","Type":"Description","Title":"CVE-2017-16682"},{"CveYear":"2017","CveId":"16682","Ordinal":"2","NoteData":"2017-12-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"16682","Ordinal":"3","NoteData":"2017-12-13","Type":"Other","Title":"Modified"}]}}}