High severity7.5NVD Advisory· Published Jan 23, 2017· Updated May 13, 2026
CVE-2017-5372
CVE-2017-5372
Description
The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/140611/SAP-NetWeaver-AS-Java-P4-MSPRUNTIMEINTERFACE-Information-Disclosure.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/93504nvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2017/Jan/50nvdMailing ListVDB Entry
- erpscan.io/advisories/erpscan-16-037-sap-java-p4-mspruntimeinterface-information-disclosure/nvd
- erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-october-2016/nvd
News mentions
0No linked articles in our index yet.