CVE-2016-4551

The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver:2004s:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_aba:7.00:sp_level_0031:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:7.00:sp_level_0031:*:*:*:*:*:*

History

21 Nov 2024, 02:52

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2016/Oct/3 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2016/Oct/3 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/93288 - () http://www.securityfocus.com/bid/93288 -
References () https://www.onapsis.com/research/security-advisories/sap-security-audit-log-invalid-address-logging - Permissions Required, Third Party Advisory () https://www.onapsis.com/research/security-advisories/sap-security-audit-log-invalid-address-logging - Permissions Required, Third Party Advisory

Information

Published : 2016-10-05 16:59

Updated : 2024-11-21 02:52


NVD link : CVE-2016-4551

Mitre link : CVE-2016-4551

CVE.ORG link : CVE-2016-4551


JSON object : View

Products Affected

sap

  • sap_basis
  • sap_aba
  • netweaver
CWE
CWE-284

Improper Access Control