Impact
The SAP Change and Transport System Attach Tool (ctsattach) contains an insecure deserialization flaw (CWE-502) that allows an authenticated user to deliver a specially crafted archive file. When the application’s library processes this file, malicious code is executed, granting the attacker remote code execution. This can lead to full compromise of confidentiality and integrity, while availability is only minimally affected.
Affected Systems
The vulnerability affects SAP SE’s SAP Change and Transport System Attach Tool (ctsattach). Any installation that includes ctsattach may be vulnerable unless the fix released in SAP Note 3773304 has been applied; specific version data is not provided, so all releases that contain ctsattach should be considered at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploits. According to the description, the attacker must be authenticated to ctsattach and provide a malicious archive; once the archive is processed, arbitrary code executes with the process’s privileges. Therefore, the attack requires valid credentials, though the description does not explicitly state that the attacker must be an insider or have compromised credentials; the likelihood of successful exploitation remains low but the impact is severe.
OpenCVE Enrichment