In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and availability.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3411869 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sap
Published: 2024-01-09T01:18:19.305Z
Updated: 2024-01-09T01:18:19.305Z
Reserved: 2024-01-01T10:54:59.645Z
Link: CVE-2024-21737
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-09T02:15:45.823
Modified: 2024-01-16T17:45:47.083
Link: CVE-2024-21737
JSON object: View
Redhat Information
No data.
CWE