5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
6.8 Medium
AI Score
Confidence
High
0.092 Low
EPSS
Percentile
94.7%
Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via a crafted request.
CPE | Name | Operator | Version |
---|---|---|---|
sap:netweaver | sap netweaver | eq | 7.02 |
sap:netweaver | sap netweaver | eq | 7.30 |
blog.onapsis.com/analyzing-sap-security-notes-october-2014-edition/
erpscan.io/advisories/erpscan-14-017-sap-netweaver-http-partial-http-post-requests-dos/
erpscan.io/advisories/erpscan-14-018-sap-netweaver-j2ee-engine-partial-http-post-requests-dos/
erpscan.io/advisories/erpscan-14-019-sap-netweaver-j2ee-engine-partial-http-post-requests-dos/
erpscan.io/advisories/erpscan-14-020-sap-netweaver-management-console-gsaop-partial-http-requests-dos/
erpscan.io/advisories/erpscan-14-021-sap-netweaver-management-console-gsaop-partial-http-post-requests-dos/
erpscan.io/press-center/blog/sap-critical-patch-update-october-2014/
service.sap.com/sap/support/notes/1986725
twitter.com/SAP_Gsupport/status/523111735637864448