CRITICAL🇵🇱 Wersja polska

CVE-2024-22127

CVSS 9.1v3.1pub. 2024-03-12upd. 2025-02-07

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.

🤖 AI Analysis
How it works

An attacker with high privileges in the system can upload a specially crafted file through the Administrator Log Viewer plugin. The file processing mechanism does not sufficiently validate its content, enabling injection of system commands (command injection, CWE-77). After command injection, the commands are executed in the context of the application server, giving the attacker the ability to run arbitrary server-side operations.

Impact

An attacker can execute arbitrary commands on the server, resulting in complete breach of confidentiality, integrity, and availability of the SAP NetWeaver AS Java application. The vulnerability can lead to data theft, system configuration modification, and complete system shutdown.

Mitigation & patch

Patches available from the vendor should be applied according to references – SAP Security Note 3433192 published as part of SAP Security Patch Day. It is recommended to apply the patch immediately and restrict access to the SAP NetWeaver administrative console exclusively to trusted users and networks.

Who is affected

SAP NetWeaver Application Server Java (Administrator Log Viewer plugin) version 7.50

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sap Netweaver Application Server Java

    APP
    Sap
    7.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-6287CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard

CVE-2010-5326CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — RCE przez Invoker Servlet bez uwierzytelnienia

CVE-2016-2386CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation

CVE-2022-22532CRITICAL9.8PL ✓same product

SAP NetWeaver AS Java — nieautoryzowane wykonanie kodu przez błąd bufora HTTP