Impact
SAP NetWeaver Business Client does not adequately validate locally stored data that is processed during application startup. An attacker with low local privileges can replace this data with crafted content, leading to arbitrary code execution when the application is launched. The vulnerability impacts confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is SAP NetWeaver Business Client from SAP SE. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Since local privileges are required, the attack vector is inferred to be local. The overall risk is significant, especially in environments where local accounts may be compromised or have higher privileges.
OpenCVE Enrichment