SAP Netweaver 7.40 SP 12 SCTC_REFRESH_EXPORT_TAB_COMP Command Injection

Discussion in 'News Aggregator' started by Packet Storm, 4 Oct 2016.

  1. Packet Storm

    Packet Storm Guest

    The SAP Netweaver version 7.40 SP 12 SCTC_REFRESH_EXPORT_TAB_COMP function does not correctly sanitize variables used when executing CALL 'SYSTEM' statement, allowing an attacker, with particular privileges, to execute any arbitrary OS command.

    Continue reading...
     

Share This Page

Loading...