CyberRota Analysis
AI-GeneratedSAP NetWeaver Business Client is vulnerable due to insufficient validation of locally stored data during application startup, allowing an attacker with low privileges to replace this data with malicious content. This flaw can lead to arbitrary code execution when the application is launched, significantly compromising the confidentiality, integrity, and availability of the system. Organizations using this software should prioritize addressing this vulnerability to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.