VYPR
High severity7.5NVD Advisory· Published Feb 15, 2017· Updated May 13, 2026

CVE-2017-5997

CVE-2017-5997

Description

The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash) via multiple msgserver/group?group= requests with a crafted size of the group parameter, aka SAP Security Note 2358972.

Affected products

3
  • SAP/Sap Kernel3 versions
    cpe:2.3:a:sap:sap_kernel:7.21:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:sap_kernel:7.21:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_kernel:7.22:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_kernel:7.42:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.