VYPR
High severity7.2NVD Advisory· Published Dec 12, 2017· Updated May 13, 2026

CVE-2017-16682

CVE-2017-16682

Description

SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.

Affected products

6
  • cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*range: >=7.00,<=7.02
    • cpe:2.3:a:sap:business_application_software_integrated_solution:7.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:business_application_software_integrated_solution:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:business_application_software_integrated_solution:7.40:*:*:*:*:*:*:*
  • cpe:2.3:a:sap:netweaver_internet_transaction_server:-:*:*:*:*:*:*:*
  • SAP/SAP NetWeaver Internet Transaction Server (ITS)v5
    Range: from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.