First published: Wed Feb 15 2017(Updated: )
The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash) via multiple msgserver/group?group= requests with a crafted size of the group parameter, aka SAP Security Note 2358972.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Kernel | =7.21 | |
SAP Kernel | =7.22 | |
SAP Kernel | =7.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5997 has been classified with a severity that can lead to denial of service, causing memory consumption and process crashes.
To mitigate CVE-2017-5997, update your SAP Kernel to a version above 7.49 as recommended in the SAP Security Note 2358972.
CVE-2017-5997 affects SAP Kernel versions 7.21 to 7.49.
CVE-2017-5997 is a denial of service vulnerability that allows remote attackers to disrupt service.
Yes, CVE-2017-5997 can be exploited remotely through crafted HTTP requests to the SAP Message Server.