CVE-2019-0265
SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49,KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49. 7.73 KERNEL from 7.21 to 7.22, 7.45, 7.49, 7.53, 7.73, 7.75.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- sap/advanced business application programming platform kernel · sap/advanced business application programming platform krnl32nuc · sap/advanced business application programming platform krnl32uc · sap/advanced business application programming platform krnl64nuc · sap/advanced business application programming platform krnl64uc
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/106972Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107364Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2729710Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943Vendor Advisory
- http://www.securityfocus.com/bid/106972Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107364Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2729710Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.