CVE-2016-9832
9.9
CRITICAL · CVSS 3.0 · EPSS 4% (pctl 90)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated by WEBGUI or Report.
Scoring
| CVSS | 9.9 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.03% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-12-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| pwc | ace-advanced business application programming |
References
- http://packetstormsecurity.com/files/140062/PwC-ACE-Software-For-SAP-Security-8.10.304-ABAP-Injection.html
- http://seclists.org/fulldisclosure/2016/Dec/33
- http://www.securityfocus.com/archive/1/539883/100/0/threaded
- http://www.securityfocus.com/archive/1/539883/30/0/threaded
- http://www.securityfocus.com/bid/94733
- https://www.esnc.de/security-advisories/vulnerability-in-pwc-ace-for-sap-security
- http://packetstormsecurity.com/files/140062/PwC-ACE-Software-For-SAP-Security-8.10.304-ABAP-Injection.html
- http://seclists.org/fulldisclosure/2016/Dec/33
- http://www.securityfocus.com/archive/1/539883/100/0/threaded
- http://www.securityfocus.com/archive/1/539883/30/0/threaded
- http://www.securityfocus.com/bid/94733
- https://www.esnc.de/security-advisories/vulnerability-in-pwc-ace-for-sap-security
→ the Explorer · watch your stack · NVD