CVE-2017-9844: Critical severity sap netweaver vulnerability
Published Jul 12, 2017
·Updated
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804.
Affected Software
1 affected component
SAP NetWeaver=7400.12.21.30308
Event History
Jul 12, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Apr 25, 2025
News Published
via The Register·03:31 PM
News Published
via The Register·03:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-9844?
CVE-2017-9844 has a high severity rating due to its potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2017-9844?
To mitigate CVE-2017-9844, apply the patches provided in SAP Security Note 2399804.
3
Who is affected by CVE-2017-9844?
CVE-2017-9844 affects SAP NetWeaver version 7400.12.21.30308.
4
What type of vulnerability is CVE-2017-9844?
CVE-2017-9844 is a remote code execution and denial of service vulnerability in SAP NetWeaver.
5
Can CVE-2017-9844 be exploited remotely?
Yes, CVE-2017-9844 can be exploited remotely by attackers sending crafted requests to the metadatauploader.