CVE-2014-0995
SAP Netweaver < 7.01 - Improper Input Validation
Title source: ruleDescription
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Core Security · textdoswindows
https://www.exploit-db.com/exploits/35000
References (8)
Scores
EPSS
0.3257
EPSS Percentile
96.8%
Classification
CWE
CWE-20
Status
draft
Affected Products (2)
sap/netweaver
< 7.01
sap/netweaver
Timeline
Published
Nov 06, 2014
Tracked Since
Feb 18, 2026