First published: Tue Sep 27 2016(Updated: )
An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP TREX | =7.10-revision_63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6137 is considered a high-severity vulnerability due to the potential for remote command execution.
To remediate CVE-2016-6137, upgrade SAP TREX to a version that is not affected by this vulnerability, specifically beyond Revision 63.
CVE-2016-6137 can be exploited by attackers to execute arbitrary operating system commands on the affected SAP TREX system.
Any organization using SAP TREX version 7.10 Revision 63 may be affected by CVE-2016-6137.
CVE-2016-6137 was disclosed in August 2016.