First published: Wed Nov 23 2016(Updated: )
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS JAVA | =7.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9562 is classified as a Denial of Service vulnerability.
To fix CVE-2016-9562, it is recommended to apply the patches provided in SAP Security Note 2313835.
CVE-2016-9562 allows remote attackers to cause a Denial of Service, leading to a null pointer exception and icman outage.
CVE-2016-9562 affects SAP NetWeaver AS JAVA version 7.40.
Yes, CVE-2016-9562 can be exploited remotely via an HTTPS request to a specific URI.