CVE-2017-6950: Critical severity SAP GUI for Windows vulnerability
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SAP GUI 7.2 through 7.5to a version that resolves this vulnerability.Patch 2407616
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6950?
CVE-2017-6950 is considered a high-severity vulnerability allowing remote code execution.
How do I fix CVE-2017-6950?
To fix CVE-2017-6950, you should upgrade to a patched version of SAP GUI, specifically newer than 7.5.
What types of attacks are possible with CVE-2017-6950?
CVE-2017-6950 allows attackers to execute arbitrary code by bypassing security restrictions using crafted ABAP code.
Which versions of SAP are affected by CVE-2017-6950?
CVE-2017-6950 affects SAP GUI versions 7.20, 7.30, 7.40_core_sp00-sp011, and 7.50_core_sp000.
What is the impact of CVE-2017-6950 on SAP users?
The impact of CVE-2017-6950 on SAP users includes potential unauthorized access and manipulation of sensitive data.