VYPR
High severity7.5NVD Advisory· Published Oct 13, 2016· Updated Jun 17, 2026

CVE-2016-3635

CVE-2016-3635

Description

SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • SAP/Netweaver2 versions
    cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.