CVE-2024-47586

MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform - DoS

Title source: llm
STIX 2.1

Description

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.

References (2)

Core 2
Core References

Scores

CVSS v3 5.3
EPSS 0.0048
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (12)
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 7.22EXT
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 7.53
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 7.54
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 7.77
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 7.89
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 7.93
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 8.04
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 9.12
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform 9.13
SAP_SE/SAP NetWeaver Application Server for ABAP and ABAP Platform KERNEL 7.22
... and 2 more
Published Nov 12, 2024
Tracked Since Feb 18, 2026