First published: Fri Apr 08 2016(Updated: )
Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the IctParseCookies function, aka SAP Security Note 2256185.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP JAVA AS | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3979 has a severity rating of medium due to its potential for denial of service impacts.
To fix CVE-2016-3979, apply the recommended patches or updates provided by SAP according to SAP Security Note 2256185.
CVE-2016-3979 affects SAP JAVA AS versions 7.2 through 7.4.
CVE-2016-3979 allows remote attackers to cause a denial of service through crafted HTTP requests.
The Internet Communication Manager (ICMAN) component is vulnerable in CVE-2016-3979.