CVE-2016-4551 describes a vulnerability in SAP NetWeaver 2004s, specifically affecting SAP_BASIS and SAP_ABA components (version 7.00 SP Level 0031). This flaw allows remote attackers to spoof IP addresses recorded in the Security Audit Log, potentially obscuring malicious activity. The vulnerability carries a CVSSv3 score of 7.5 (HIGH), indicating a high-severity issue with a network attack vector and low attack complexity, requiring no user interaction. While it doesn't directly impact confidentiality or availability, successful exploitation could lead to high integrity impact by compromising the reliability of audit logs. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2004sCPE matchmatch criteria | cpe:2.3:a:sap:netweaver:2004s:*:*:*:*:*:*:* | ||
7.00CPE matchmatch criteria | cpe:2.3:a:sap:sap_aba:7.00:sp_level_0031:*:*:*:*:*:* | ||
7.00CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:7.00:sp_level_0031:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.