Impact
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low‑privileged attacker who can manipulate a backend can trigger the affected functionality and thereby execute arbitrary commands on the victim's machine. This allows the attacker to compromise confidentiality, integrity, and availability of the affected service.
Affected Systems
SAP NetWeaver, specifically the SAP GUI for Java component managed by SAP SE. No specific versions are listed, so all current releases of this product are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9 indicates a very high severity. Because the exploitation requires only manipulation of a connected backend system, an attacker who can glean or inject commands into that backend with even low privileges can achieve remote command execution on the client. The EPSS score is not available and the threat is not listed in CISA KEV, meaning no known widespread exploitation yet, but the high CVSS warrants close attention. Mitigation requires prompt patching and strict access controls on backend connections.
OpenCVE Enrichment