An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
700CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:sap_basis:*:*:* | ||
701CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:701:*:*:*:sap_basis:*:*:* | ||
702CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:702:*:*:*:sap_basis:*:*:* | ||
731CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:sap_basis:*:*:* | ||
740CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:sap_basis:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.