root@deepquest.code511.com:~# 

>> SAP Netweaver 7.40 SP 12 SCTC_TMS_MAINTAIN_ALOG Command Injection

The SAP Netweaver version 7.40 SP 12 SCTC_TMS_MAINTAIN_ALOG function does not correctly sanitize variables used when executing CALL ‘SYSTEM’ statement, allowing an attacker, with particular privileges, to execute any arbitrary OS command.

> POST_COMMENT