First published: Tue Mar 12 2024(Updated: )
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS JAVA | ||
SAP NetWeaver AS JAVA | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22127 is considered a high severity vulnerability due to its potential for command injection via file uploads.
To fix CVE-2024-22127, apply the latest security updates provided by SAP for NetWeaver AS Java version 7.50.
CVE-2024-22127 affects SAP NetWeaver AS Java version 7.50 and can impact systems where this version is deployed.
Exploitation of CVE-2024-22127 can lead to unauthorized command execution, potentially compromising the entire server.
CVE-2024-22127 can be exploited by attackers who possess high privileges in the SAP NetWeaver environment.