CVE-2016-3980: Input Validation
Published Apr 8, 2016
·Updated
The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547.
Affected Software
1 affected component
SAP Application Server Java>=7.2<=7.4
Event History
Apr 8, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3980?
CVE-2016-3980 has a severity rating that indicates it can lead to a denial of service through process crashes.
2
How do I fix CVE-2016-3980?
To fix CVE-2016-3980, it is recommended to apply patches provided in SAP Security Note 2259547.
3
Which versions are affected by CVE-2016-3980?
CVE-2016-3980 affects SAP JAVA AS versions 7.2 through 7.4.
4
What type of attack does CVE-2016-3980 enable?
CVE-2016-3980 enables remote attackers to execute denial of service attacks by sending crafted HTTP requests.
5
Is there a known exploit for CVE-2016-3980?
Yes, there are known exploit techniques that can trigger a denial of service condition in affected SAP JAVA AS versions.