Описание
SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.
Ссылки
- Broken LinkThird Party AdvisoryVDB Entry
- https://erpscan.io/advisories/erpscan-17-010-sap-netweaver-abap-dispwork-crash-using-cl_java_script/Broken LinkExploitThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- https://erpscan.io/advisories/erpscan-17-010-sap-netweaver-abap-dispwork-crash-using-cl_java_script/Broken LinkExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sap:netweaver_abap:7.40:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00269
Низкий
2.7 Low
CVSS3
4 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.
EPSS
Процентиль: 50%
0.00269
Низкий
2.7 Low
CVSS3
4 Medium
CVSS2
Дефекты
NVD-CWE-noinfo