CVE-2017-11459: SAP Trex

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.

Affected products

  • SAP Trex: version 7.10 only

Published 2017-07-25. Last modified 2026-06-17.