SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability
BID:102143
Info
SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability
| Bugtraq ID: | 102143 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-16682 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2017 12:00AM |
| Updated: | Dec 19 2017 10:01PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP NetWeaver 0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability
SAP Netweaver is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
SAP Netweaver is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Netweaver CVE-2017-16682 Remote Code Injection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2526781 (SAP)
- SAP Security Patch Day �?? December 2017 (SAP)