CVE-2009-4603
Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console…
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console shutdown) via a crafted request. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- sap/sap kernel
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37684Vendor Advisory
- http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf
- http://www.securityfocus.com/bid/37286
- http://www.securitytracker.com/id?1023319
- https://service.sap.com/sap/support/notes/1302231
- http://secunia.com/advisories/37684Vendor Advisory
- http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf
- http://www.securityfocus.com/bid/37286
- http://www.securitytracker.com/id?1023319
- https://service.sap.com/sap/support/notes/1302231
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.