CVE-2016-7435
CVE-2016-7435
The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://seclists.org/fulldisclosure/2016/Oct/0http://seclists.org/fulldisclosure/2016/Oct/1http://seclists.org/fulldisclosure/2016/Oct/2https://www.onapsis.com/blog/analyzing-sap-security-notes-march-2016https://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctcrefreshcheckenvhttps://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctcrefreshexporttabcomphttps://www.onapsis.com/research/security-advisories/sap-os-command-injection-sctctmsmaintainaloghttp://www.securityfocus.com/bid/93272