CVE-2014-0995: Input Validation
Published Nov 6, 2014
·Updated
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern.
Affected Software
2 affected components
SAP NetWeaver<=7.01
SAP NetWeaver=7.20
Event History
Nov 6, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0995?
CVE-2014-0995 is classified as a denial of service vulnerability.
2
How do I fix CVE-2014-0995?
To mitigate CVE-2014-0995, it is recommended to update SAP Netweaver to a version beyond 7.20.
3
What versions of SAP Netweaver are affected by CVE-2014-0995?
CVE-2014-0995 affects SAP Netweaver versions 7.20, 7.01, and earlier.
4
What type of attack does CVE-2014-0995 enable?
CVE-2014-0995 enables remote attackers to cause a denial of service through uncontrolled recursion.
5
Can CVE-2014-0995 be exploited remotely?
Yes, CVE-2014-0995 can be exploited by remote attackers.