Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39w3-fg6q-3vw3

Опубликовано: 10 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

EPSS

Процентиль: 30%
0.00368
Низкий

7.7 High

CVSS3

Дефекты

CWE-606

Связанные уязвимости

CVSS3: 7.7
nvd
6 месяцев назад

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

CVSS3: 7.7
fstec
6 месяцев назад

Уязвимость программного средства управления поставками компаний SAP Supply Chain Management, связанная с непроверенным вводом данных, используемых как условие выполнения цикла, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00368
Низкий

7.7 High

CVSS3

Дефекты

CWE-606