CVE-2024-22127
Published Mar 12, 2024
Last updated 2 months ago
Overview
- Description
- SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.
- Source
- cna@sap.com
- NVD status
- Awaiting Analysis
Risk scores
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Weaknesses
- cna@sap.com
- CWE-77
Social media
- Hype score
1
Actively exploited CVE : CVE-2024-22127
@transilienceai
Nov 14, 2024 5:18 AM
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2024-22127
@transilienceai
Nov 12, 2024 5:18 AM
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-22127
@transilienceai
Nov 10, 2024 5:18 PM
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-22127
@transilienceai
Nov 8, 2024 5:15 PM
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-22127
@transilienceai
Nov 4, 2024 12:01 AM
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes