CVE-2024-22127 CRITICAL

CVE-2024-22127: Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)

Vendor Sap_Se
Product SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
Weakness CWE-77
Published March 12, 2024
Last update September 26, 2024

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

Description

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.

Key dates

Disclosure timeline

March 12, 2024 CVE published
September 26, 2024 Record updated