CVE-2016-10304: Medium severity sap netweaver as for java vulnerability
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10304?
CVE-2016-10304 is classified as a medium severity vulnerability resulting in denial of service.
How do I fix CVE-2016-10304?
To mitigate CVE-2016-10304, it is recommended to apply the latest SAP patches as specified in SAP Security Note 2315788.
Who can exploit CVE-2016-10304?
CVE-2016-10304 can be exploited by remote authenticated users who have access to the SAP NetWeaver AS JAVA 7.5 component.
What impact does CVE-2016-10304 have on systems?
Exploitation of CVE-2016-10304 can lead to an out-of-memory error and instability in the SAP NetWeaver AS JAVA service.
In which versions of SAP is CVE-2016-10304 found?
CVE-2016-10304 affects SAP NetWeaver AS JAVA version 7.50.