CVE-2016-9832

CRITICAL

PwC ACE-ABAP 8.10.304 - Authenticated ABAP Injection via SAPGUI or ICF

Title source: llm
STIX 2.1

Description

PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated by WEBGUI or Report.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/archive/1/539883/30/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94733
Third Party Advisory, VDB Entry mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Dec/33
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/539883/100/0/threaded

Scores

CVSS v3 9.9
EPSS 0.0403
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
pwc/ace-advanced_business_application_programming 8.10.304
Published Dec 10, 2016
Tracked Since Feb 18, 2026