CVE-2016-3979: Input Validation
Published Apr 8, 2016
·Updated
Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the IctParseCookies function, aka SAP Security Note 2256185.
Affected Software
1 affected component
SAP JAVA AS=7.4
Event History
Apr 8, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3979?
CVE-2016-3979 has a severity rating of medium due to its potential for denial of service impacts.
2
How do I fix CVE-2016-3979?
To fix CVE-2016-3979, apply the recommended patches or updates provided by SAP according to SAP Security Note 2256185.
3
What systems are affected by CVE-2016-3979?
CVE-2016-3979 affects SAP JAVA AS versions 7.2 through 7.4.
4
What kind of attack does CVE-2016-3979 facilitate?
CVE-2016-3979 allows remote attackers to cause a denial of service through crafted HTTP requests.
5
What component is vulnerable in CVE-2016-3979?
The Internet Communication Manager (ICMAN) component is vulnerable in CVE-2016-3979.