SAP Netweaver 7.40 SP 12 SCTC_REFRESH_EXPORT_TAB_COMP Command Injection
Posted by deepcore on October 4, 2016 – 6:58 pm
The SAP Netweaver version 7.40 SP 12 SCTC_REFRESH_EXPORT_TAB_COMP function does not correctly sanitize variables used when executing CALL ‘SYSTEM’ statement, allowing an attacker, with particular privileges, to execute any arbitrary OS command.
Post a reply
You must be logged in to post a comment.