peter bassill · operator
$ cve CVE-2016-9832 JSON

CVE-2016-9832

9.9
CRITICAL · CVSS 3.0 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.9), but no sign of active exploitation.

Description

PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated by WEBGUI or Report.

Scoring

CVSS9.9 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS4.03% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploitnone known
Published2016-12-10
Last modified2026-06-17

Affected (1)

VendorProduct
pwcace-advanced business application programming

References

→ the Explorer  ·  watch your stack  ·  NVD