An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2016/Aug/85 | third party advisory mailing list |
http://onapsis.com/research/security-advisories/sap-trex-remote-command-execution | third party advisory permissions required |
http://packetstormsecurity.com/files/138436/SAP-TREX-7.10-Revision-63-Remote-Command-Execution.html | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2016/Aug/113 | third party advisory mailing list |