SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file contained in the SAR archive. It is possible to append a tampered file to the SAR archive using SAPCAR tool and during the extraction, digital signature verification fails but the tampered file is extracted.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2017-12-12T14:00:00Z

Updated: 2024-09-17T00:31:20.128Z

Reserved: 2017-11-09T00:00:00

Link: CVE-2017-16691

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-12-12T14:29:00.700

Modified: 2018-01-04T18:39:52.857

Link: CVE-2017-16691

cve-icon Redhat

No data.