PT-2016-5789 · Sap · Sap As Java

Dmitry Yudin

+1

·

Publicado

2016-04-08

·

Atualizado

2018-12-10

·

CVE-2016-3979

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP JAVA AS versions 7.2 through 7.4
Description The issue allows remote attackers to cause a denial of service, resulting in heap memory corruption and process crash, via a crafted HTTP request. This is related to the IctParseCookies function.
Recommendations For SAP JAVA AS versions 7.2 through 7.4, consider applying the fix provided in SAP Security Note 2256185 to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3979

Produtos afetados

Sap As Java