CVE-2017-16691

Severity
6.5MEDIUM
EPSS
0.4%
top 41.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 14

Description

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file contained in the SAR archive. It is possible to append a tampered file to the SAR archive using SAPCAR tool and during the extraction, digital signature verification fails but the tampered file is extracted.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5sap/sap_note_assistantSAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52

🔴Vulnerability Details

2
GHSA
GHSA-4f5h-cfp2-m9r7: SAP Note Assistant tool (SAP BASIS from 72022-05-14
CVEList
CVE-2017-16691: SAP Note Assistant tool (SAP BASIS from 72017-12-12
CVE-2017-16691 (MEDIUM CVSS 6.5) | SAP Note Assistant tool (SAP BASIS | cvebase.io