CVE-2024-22132

HIGH

SAP IDES ECC - OS Command Injection

Title source: llm
STIX 2.1

Description

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behaviour of the system by executing malicious code which can potentially escalate privileges with low impact on confidentiality, integrity and availability of the system.

References (2)

Core 2

Scores

CVSS v3 7.4
EPSS 0.0031
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
sap/ides_ecc
Published Feb 13, 2024
Tracked Since Feb 18, 2026