TROYANOSYVIRUS
Back to CVEs

CVE-2024-22127

CRITICAL
9.1

Description

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.

CVE Details

CVSS v3.1 Score9.1
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published3/12/2024
Last Modified2/7/2025
Sourcenvd
Honeypot Sightings0

Affected Products

sap:netweaver_application_server_java

Weaknesses (CWE)

CWE-77

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.