Description
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19723 | SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application. |
References
History
Fri, 07 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Application Server Java |
|
| CPEs | cpe:2.3:a:sap:netweaver_application_server_java:7.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap netweaver Application Server Java |
Thu, 26 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Thu, 26 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application. | SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application. |
| Weaknesses | CWE-77 |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-09-26T18:27:18.285Z
Reserved: 2024-01-05T10:21:35.256Z
Link: CVE-2024-22127
Updated: 2024-08-01T22:35:34.821Z
Status : Analyzed
Published: 2024-03-12T01:15:49.060
Modified: 2025-02-07T17:25:17.913
Link: CVE-2024-22127
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD