First published: Thu Oct 13 2016(Updated: )
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3635 is considered a critical vulnerability due to its potential to allow unauthorized remote execution of arbitrary function modules.
To fix CVE-2016-3635, ensure you apply the latest security patches provided by SAP for NetWeaver 7.4.
CVE-2016-3635 affects remote authenticated users of SAP NetWeaver 7.4.
CVE-2016-3635 can enable attackers to bypass access controls and execute arbitrary Remote Function Modules.
Currently, the recommended solution for CVE-2016-3635 is to apply security updates, as no official workarounds are documented.