CVE-2016-7435: Critical severity sap netweaver vulnerability
The (1) SCTCREFRESHEXPORTTABCOMP, (2) SCTCREFRESHCHECKENV, and (3) SCTCTMSMAINTAINALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7435?
CVE-2016-7435 has been categorized as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2016-7435?
To fix CVE-2016-7435, ensure that you update to the latest patch release of SAP NetWeaver that addresses this vulnerability.
Who is affected by CVE-2016-7435?
CVE-2016-7435 affects remote authenticated users with certain permissions in SAP NetWeaver 7.40 SP 12.
What can an attacker do with CVE-2016-7435?
An attacker exploiting CVE-2016-7435 can execute arbitrary commands on the affected system.
Which functions are vulnerable in CVE-2016-7435?
The functions SCTC_REFRESH_EXPORT_TAB_COMP, SCTC_REFRESH_CHECK_ENV, and SCTC_TMS_MAINTAIN_ALOG in the SCTC subpackage are vulnerable in CVE-2016-7435.