An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/138436/SAP-TREX-7.10-Revision-63-Remote-Command-Execution.html | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2016/Aug/85 | Third Party Advisory |
http://seclists.org/fulldisclosure/2016/Aug/113 | Third Party Advisory |
http://onapsis.com/research/security-advisories/sap-trex-remote-command-execution | Permissions Required Third Party Advisory |
Configurations
Information
Published : 2016-09-27 08:59
Updated : 2016-09-28 07:29
NVD link : CVE-2016-6137
Mitre link : CVE-2016-6137
JSON object : View
CWE
Products Affected
sap
- trex