First published: Mon Apr 10 2017(Updated: )
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Java Application Server | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10304 is classified as a medium severity vulnerability resulting in denial of service.
To mitigate CVE-2016-10304, it is recommended to apply the latest SAP patches as specified in SAP Security Note 2315788.
CVE-2016-10304 can be exploited by remote authenticated users who have access to the SAP NetWeaver AS JAVA 7.5 component.
Exploitation of CVE-2016-10304 can lead to an out-of-memory error and instability in the SAP NetWeaver AS JAVA service.
CVE-2016-10304 affects SAP NetWeaver AS JAVA version 7.50.