Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-16682


SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.


Published

2017-12-12T14:29:00.403

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_internet_transaction_server - Yes
Application sap business_application_software_integrated_solution ≤ 7.02 Yes
Application sap business_application_software_integrated_solution ≤ 7.52 Yes
Application sap business_application_software_integrated_solution 7.30 Yes
Application sap business_application_software_integrated_solution 7.31 Yes
Application sap business_application_software_integrated_solution 7.40 Yes

References