CVE-2017-16682

Current Description

SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.

Basic Data

PublishedDecember 12, 2017
Last ModifiedDecember 22, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-94
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationSINGLE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score6.5
SeverityMEDIUM
Exploitability Score8.0
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

CVSS 3 - Version3.0
CVSS 3 - Vector StringCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 3 - Attack VectorNETWORK
CVSS 3 - Attack ComplexityLOW
CVSS 3 - Privileges RequiredHIGH
CVSS 3 - User InteractionNONE
CVSS 3 - ScopeUNCHANGED
CVSS 3 - Confidentiality ImpactHIGH
CVSS 3 - Integrity ImpactHIGH
CVSS 3 - Availability ImpactHIGH
CVSS 3 - Base Score7.2
CVSS 3 - Base SeverityHIGH
Exploitability Score1.2
Base SeverityHIGH

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationSapNetweaver Internet Transaction Server-*******
  • OR - Configuration 2
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationSapBusiness Application Software Integrated Solution********7.007.02
    2.3ApplicationSapBusiness Application Software Integrated Solution7.30*******
    2.3ApplicationSapBusiness Application Software Integrated Solution7.31*******
    2.3ApplicationSapBusiness Application Software Integrated Solution7.40*******
    2.3ApplicationSapBusiness Application Software Integrated Solution********7.507.52

Vulnerable Software List

VendorProductVersions
Sap Netweaver Internet Transaction Server -
Sap Business Application Software Integrated Solution *, 7.30, 7.31, 7.40

References

NameSourceURLTags
102143http://www.securityfocus.com/bid/102143BIDThird Party Advisory VDB Entry
https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/CONFIRMVendor Advisory
https://launchpad.support.sap.com/#/notes/2526781https://launchpad.support.sap.com/#/notes/2526781CONFIRMPermissions Required