SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0265

SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

MEDIUM 4.9EPSS 2.05%

Does this matter?

Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.

Description

SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49,KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49. 7.73 KERNEL from 7.21 to 7.22, 7.45, 7.49, 7.53, 7.73, 7.75.

CVSS 3.0
4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS
2.05% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
sap/advanced business application programming platform kernel · sap/advanced business application programming platform krnl32nuc · sap/advanced business application programming platform krnl32uc · sap/advanced business application programming platform krnl64nuc · sap/advanced business application programming platform krnl64uc
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.