SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-07-25T18:00:00

Updated: 2024-08-05T18:12:39.837Z

Reserved: 2017-07-19T00:00:00

Link: CVE-2017-11459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-07-25T18:29:01.167

Modified: 2018-12-10T19:29:19.783

Link: CVE-2017-11459

cve-icon Redhat

No data.