Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7.53) allows an attacker to prevent users from accessing its services through a denial of service.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2848498 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-01-14 10:15
Updated : 2020-01-24 05:15
NVD link : CVE-2020-6304
Mitre link : CVE-2020-6304
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
sap
- netweaver_internet_communication_manager_\(krnl64nuc\)
- netweaver_internet_communication_manager_\(krnl32uc\)
- netweaver_internet_communication_manager_\(kernel\)
- netweaver_internet_communication_manager_\(krnl64uc\)
- netweaver_internet_communication_manager_\(krnl32nuc\)