PT-2016-5789 · Sap · Sap As Java

Dmitry Yudin

+1

·

Published

2016-04-08

·

Updated

2018-12-10

·

CVE-2016-3979

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP JAVA AS versions 7.2 through 7.4
Description The issue allows remote attackers to cause a denial of service, resulting in heap memory corruption and process crash, via a crafted HTTP request. This is related to the IctParseCookies function.
Recommendations For SAP JAVA AS versions 7.2 through 7.4, consider applying the fix provided in SAP Security Note 2256185 to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3979

Affected Products

Sap As Java