| Title | SAP NetWeaver AS for Java における脆弱性 |
|---|---|
| Summary | SAP NetWeaver AS for Java (Http Service Monitoring Filter) には、不特定の脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | July 13, 2021, midnight |
| Registration Date | May 10, 2022, 6:05 p.m. |
| Last Update | May 10, 2022, 6:05 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.5 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS2.0 : 警告 | |
| Score | 5 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| SAP |
| SAP Netweaver Application Server Java 7.50 |
| SAP Netweaver Application Server Java 7.10 |
| SAP Netweaver Application Server Java 7.20 |
| SAP Netweaver Application Server Java 7.30 |
| SAP Netweaver Application Server Java 7.31 |
| SAP Netweaver Application Server Java 7.40 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2022年04月19日] 掲載 | April 19, 2022, 11:02 a.m. |
| Summary | SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability. |
|---|---|
| Publication Date | July 14, 2021, 9:15 p.m. |
| Registration Date | July 15, 2021, 10 a.m. |
| Last Update | Nov. 21, 2024, 3:09 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:netweaver_application_server_java:7.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:netweaver_application_server_java:7.11:*:*:*:*:*:*:* | |||||