SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

Summary

SAP has released security updates to fix several vulnerabilities, notably a critical flaw in its Extended Passport (EPP) Processing. This vulnerability, rated CVSS 10.0, allows for unauthenticated remote code execution due to memory corruption.

IFF Assessment

FOE

A CVSS 10.0 vulnerability that allows for unauthenticated remote code execution represents a critical threat to SAP systems and data.

Severity

10.0 Critical

Defender Context

Defenders should prioritize patching SAP systems, particularly those using Extended Passport Processing, to mitigate the risk of unauthenticated remote code execution. This vulnerability highlights the ongoing severe risks associated with unpatched enterprise software and the importance of timely vulnerability management.

Read Full Story →