SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
An attacker with high privileges in the system can upload a specially crafted file through the Administrator Log Viewer plugin. The file processing mechanism does not sufficiently validate its content, enabling injection of system commands (command injection, CWE-77). After command injection, the commands are executed in the context of the application server, giving the attacker the ability to run arbitrary server-side operations.
An attacker can execute arbitrary commands on the server, resulting in complete breach of confidentiality, integrity, and availability of the SAP NetWeaver AS Java application. The vulnerability can lead to data theft, system configuration modification, and complete system shutdown.
Patches available from the vendor should be applied according to references – SAP Security Note 3433192 published as part of SAP Security Patch Day. It is recommended to apply the patch immediately and restrict access to the SAP NetWeaver administrative console exclusively to trusted users and networks.
SAP NetWeaver Application Server Java (Administrator Log Viewer plugin) version 7.50
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSap Netweaver Application Server Java
APPSap7.5
Related vulnerabilities
SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard
SAP NetWeaver AS Java — RCE przez Invoker Servlet bez uwierzytelnienia
SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40
SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation
SAP NetWeaver AS Java — nieautoryzowane wykonanie kodu przez błąd bufora HTTP