CVE-2024-21737

In SAP Application Interface Framework File Adapter - version 702, ahigh privilege user can use a function module to traverse through various layers and execute OS commands directly. By this,such user can controlthe behaviour of the application. This leads to considerable impact on confidentiality, integrity and availability.

Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
sapCNA
8.4 HIGH
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---