PT-2016-5789 · Sap · Sap As Java
Dmitry Yudin
+1
·
Publicado
2016-04-08
·
Atualizado
2018-12-10
·
CVE-2016-3979
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SAP JAVA AS versions 7.2 through 7.4
Description
The issue allows remote attackers to cause a denial of service, resulting in heap memory corruption and process crash, via a crafted HTTP request. This is related to the
IctParseCookies function.Recommendations
For SAP JAVA AS versions 7.2 through 7.4, consider applying the fix provided in SAP Security Note 2256185 to resolve the issue.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap As Java