Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-7435

The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.1%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 9.0
References
Products affected by CVE-2016-7435
  • Sap » Netweaver » Version: 7.40
    cpe:2.3:a:sap:netweaver:7.40


Contact Us

Shodan ® - All rights reserved