cve/2024/CVE-2024-22127.md
2024-05-25 21:48:12 +02:00

18 lines
972 B
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-22127](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22127)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20NetWeaver%20AS%20Java%20(Administrator%20Log%20Viewer%20plug-in)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%207.50%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-94%3A%20Improper%20Control%20of%20Generation%20of%20Code%20('Code%20Injection')&color=brighgreen)
### Description
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds