CVE-2016-7437: Low severity sap netweaver vulnerability
SAP Netweaver 7.40 improperly logs (1) DUI and (2) DUJ events in the SAP Security Audit Log as non-critical, which might allow local users to hide rejected attempts to execute RFC function callbacks by leveraging filtering of non-critical events in audit analysis reports, aka SAP Security Note 2252312.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7437?
CVE-2016-7437 is considered a medium severity vulnerability due to the potential for local users to hide unauthorized access attempts.
How do I fix CVE-2016-7437?
Fixing CVE-2016-7437 involves applying security patches related to the SAP Security Log configuration.
What software versions are affected by CVE-2016-7437?
CVE-2016-7437 affects SAP Netweaver version 7.40.
What impact does CVE-2016-7437 have?
The impact of CVE-2016-7437 is that it allows local users to manipulate audit log entries, potentially hiding unauthorized actions.
Is there a workaround for CVE-2016-7437?
A recommended workaround for CVE-2016-7437 is to monitor audit logs manually and adjust user permissions to limit access.