CVE-2016-3635: High severity sap netweaver vulnerability
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3635?
CVE-2016-3635 is considered a critical vulnerability due to its potential to allow unauthorized remote execution of arbitrary function modules.
How do I fix CVE-2016-3635?
To fix CVE-2016-3635, ensure you apply the latest security patches provided by SAP for NetWeaver 7.4.
Who is affected by CVE-2016-3635?
CVE-2016-3635 affects remote authenticated users of SAP NetWeaver 7.4.
What types of attacks can CVE-2016-3635 enable?
CVE-2016-3635 can enable attackers to bypass access controls and execute arbitrary Remote Function Modules.
Is there a workaround for CVE-2016-3635?
Currently, the recommended solution for CVE-2016-3635 is to apply security updates, as no official workarounds are documented.