CVE-2016-4551
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
05/10/2016
Last modified:
12/04/2025
Description
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:netweaver:2004s:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:sap_aba:7.00:sp_level_0031:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:sap_basis:7.00:sp_level_0031:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/fulldisclosure/2016/Oct/3
- http://www.securityfocus.com/bid/93288
- https://www.onapsis.com/research/security-advisories/sap-security-audit-log-invalid-address-logging
- http://seclists.org/fulldisclosure/2016/Oct/3
- http://www.securityfocus.com/bid/93288
- https://www.onapsis.com/research/security-advisories/sap-security-audit-log-invalid-address-logging



