Описание
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042.
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sap:sso_authentication_library:2.0:*:*:*:*:*:*:*
cpe:2.3:a:sap:sso_authentication_library:3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.36219
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 7.5
github
больше 4 лет назад
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042.
EPSS
Процентиль: 98%
0.36219
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-770