CVE-2014-0995

SAP Netweaver < 7.01 - Improper Input Validation

Title source: rule

Description

The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textdoswindows
https://www.exploit-db.com/exploits/35000

Scores

EPSS 0.3257
EPSS Percentile 96.8%

Classification

CWE
CWE-20
Status draft

Affected Products (2)

sap/netweaver < 7.01
sap/netweaver

Timeline

Published Nov 06, 2014
Tracked Since Feb 18, 2026