CVE-2017-6950
9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.79% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-732 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-03-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | gui for windows |
References
- http://www.securityfocus.com/bid/96872
- http://www.securitytracker.com/id/1038122
- https://erpscan.io/advisories/erpscan-17-011-sap-gui-versions-remote-code-execution-bypass-security-policy/
- http://www.securityfocus.com/bid/96872
- http://www.securitytracker.com/id/1038122
- https://erpscan.io/advisories/erpscan-17-011-sap-gui-versions-remote-code-execution-bypass-security-policy/
→ the Explorer · watch your stack · NVD