CVE-2017-9845: High severity sap netweaver vulnerability
Published Jul 12, 2017
·Updated
disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG request, aka SAP Security Note 2405918.
Affected Software
1 affected component
SAP NetWeaver=7.40
Event History
Jul 12, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9845?
CVE-2017-9845 is rated as a medium severity vulnerability due to its potential for denial of service attacks.
2
How do I fix CVE-2017-9845?
To fix CVE-2017-9845, it is recommended to apply the patches provided in SAP Security Note 2405918.
3
What type of attack does CVE-2017-9845 enable?
CVE-2017-9845 allows remote attackers to execute a denial of service attack through crafted DIAG requests.
4
Which SAP product is affected by CVE-2017-9845?
CVE-2017-9845 affects SAP NetWeaver version 7.40.
5
What is the impact of exploiting CVE-2017-9845?
Exploiting CVE-2017-9845 can lead to resource consumption and service disruption for the affected SAP system.