CVE-2016-3635 Information
Feb 14, 2021
cve
Description
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly aka SAP Security Note 2139366.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://seclists.org/fulldisclosure/2016/Oct/48 http://www.securityfocus.com/bid/93501 https://www.onapsis.com/research/security-advisories/sap-ucon-security-protection-bypass
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.5
Share on: