CVE-2017-7696

HIGH

SAP AS JAVA SSO Authentication Library <3.0 - DoS

Title source: llm
STIX 2.1

Description

SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0179
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (2)
sap/sso_authentication_library 2.0
sap/sso_authentication_library 3.0
Published Apr 14, 2017
Tracked Since Feb 18, 2026