CVE-2017-7717: SQL Injection
Published Apr 14, 2017
·Updated
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.
Affected Software
1 affected component
SAP NetWeaver Application Server Java=7.40
Event History
Apr 14, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7717?
CVE-2017-7717 is considered to have a high severity due to its potential for remote unauthorized SQL command execution.
2
How do I fix CVE-2017-7717?
To fix CVE-2017-7717, apply the relevant SAP Security Note 2356504 to your SAP NetWeaver AS Java 7.4 installation.
3
Who is affected by CVE-2017-7717?
CVE-2017-7717 affects remote authenticated users of SAP NetWeaver AS Java 7.4.
4
What kind of vulnerability is CVE-2017-7717?
CVE-2017-7717 is an SQL injection vulnerability that allows users to execute arbitrary SQL commands.
5
Can CVE-2017-7717 be exploited remotely?
Yes, CVE-2017-7717 can be exploited remotely by authenticated users through the vulnerable method.