SAP Netweaver 7.40 SP 12 SCTC_TMS_MAINTAIN_ALOG Command Injection

Discussion in 'News Aggregator' started by Packet Storm, 4 Oct 2016.

  1. Packet Storm

    Packet Storm Guest

    The SAP Netweaver version 7.40 SP 12 SCTC_TMS_MAINTAIN_ALOG function does not correctly sanitize variables used when executing CALL 'SYSTEM' statement, allowing an attacker, with particular privileges, to execute any arbitrary OS command.

    Continue reading...
     

Share This Page

Loading...