First published: Fri Jul 06 2007(Updated: )
Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attackers to cause a denial of service (process crash) via a URI of a certain length that contains a sap-isc-key parameter, related to configuration of a web cache.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows | ||
SAP NetWeaver Internet Communication Manager | ||
SAP Web Application Server | =6.10 | |
SAP Web Application Server | =6.20 | |
SAP Web Application Server | =6.40 | |
SAP Web Application Server | =7.0 | |
SAP Web Application Server | =7.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3615 is considered a high severity vulnerability as it allows remote attackers to cause a denial of service.
To fix CVE-2007-3615, ensure that you apply the latest security patches from SAP for your version of the SAP Web Application Server.
CVE-2007-3615 affects the SAP Internet Communication Manager and SAP Web Application Server versions 6.10, 6.20, 6.40, and 7.0.
Exploiting CVE-2007-3615 can lead to a denial of service, resulting in the affected process crashing.
Yes, CVE-2007-3615 has been observed primarily in Windows environments running specific versions of SAP products.