Описание
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Ссылки
- Permissions Required
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 23.0.0 (исключая)
cpe:2.3:a:sap:approuter:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 14%
0.00226
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 4.3
github
около 1 месяца назад
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.
EPSS
Процентиль: 14%
0.00226
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-770