Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-5372

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-5372
  • Sap » Netweaver » Version: N/A
    cpe:2.3:a:sap:netweaver:-
  • Sap » Netweaver » Version: 2004s
    cpe:2.3:a:sap:netweaver:2004s
  • Sap » Netweaver » Version: 4.0
    cpe:2.3:a:sap:netweaver:4.0
  • Sap » Netweaver » Version: 6.4
    cpe:2.3:a:sap:netweaver:6.4
  • Sap » Netweaver » Version: 600
    cpe:2.3:a:sap:netweaver:600
  • Sap » Netweaver » Version: 602
    cpe:2.3:a:sap:netweaver:602
  • Sap » Netweaver » Version: 603
    cpe:2.3:a:sap:netweaver:603
  • Sap » Netweaver » Version: 604
    cpe:2.3:a:sap:netweaver:604
  • Sap » Netweaver » Version: 605
    cpe:2.3:a:sap:netweaver:605
  • Sap » Netweaver » Version: 606
    cpe:2.3:a:sap:netweaver:606
  • Sap » Netweaver » Version: 617
    cpe:2.3:a:sap:netweaver:617
  • Sap » Netweaver » Version: 618
    cpe:2.3:a:sap:netweaver:618
  • Sap » Netweaver » Version: 7.0
    cpe:2.3:a:sap:netweaver:7.0
  • Sap » Netweaver » Version: 7.01
    cpe:2.3:a:sap:netweaver:7.01
  • Sap » Netweaver » Version: 7.02
    cpe:2.3:a:sap:netweaver:7.02
  • Sap » Netweaver » Version: 7.03
    cpe:2.3:a:sap:netweaver:7.03
  • Sap » Netweaver » Version: 7.1
    cpe:2.3:a:sap:netweaver:7.1
  • Sap » Netweaver » Version: 7.10
    cpe:2.3:a:sap:netweaver:7.10
  • Sap » Netweaver » Version: 7.11
    cpe:2.3:a:sap:netweaver:7.11
  • Sap » Netweaver » Version: 7.2
    cpe:2.3:a:sap:netweaver:7.2
  • Sap » Netweaver » Version: 7.20
    cpe:2.3:a:sap:netweaver:7.20
  • Sap » Netweaver » Version: 7.22ext
    cpe:2.3:a:sap:netweaver:7.22ext
  • Sap » Netweaver » Version: 7.3
    cpe:2.3:a:sap:netweaver:7.3
  • Sap » Netweaver » Version: 7.30
    cpe:2.3:a:sap:netweaver:7.30
  • Sap » Netweaver » Version: 7.31
    cpe:2.3:a:sap:netweaver:7.31
  • Sap » Netweaver » Version: 7.4
    cpe:2.3:a:sap:netweaver:7.4
  • Sap » Netweaver » Version: 7.40
    cpe:2.3:a:sap:netweaver:7.40
  • Sap » Netweaver » Version: 7.41
    cpe:2.3:a:sap:netweaver:7.41
  • Sap » Netweaver » Version: 7.49
    cpe:2.3:a:sap:netweaver:7.49
  • Sap » Netweaver » Version: 7.5
    cpe:2.3:a:sap:netweaver:7.5
  • Sap » Netweaver » Version: 7.50
    cpe:2.3:a:sap:netweaver:7.50
  • Sap » Netweaver » Version: 7.51
    cpe:2.3:a:sap:netweaver:7.51
  • Sap » Netweaver » Version: 7.52
    cpe:2.3:a:sap:netweaver:7.52
  • Sap » Netweaver » Version: 7.53
    cpe:2.3:a:sap:netweaver:7.53
  • Sap » Netweaver » Version: 7.77
    cpe:2.3:a:sap:netweaver:7.77
  • Sap » Netweaver » Version: 7.81
    cpe:2.3:a:sap:netweaver:7.81
  • Sap » Netweaver » Version: 7.85
    cpe:2.3:a:sap:netweaver:7.85
  • Sap » Netweaver » Version: 7.86
    cpe:2.3:a:sap:netweaver:7.86
  • Sap » Netweaver » Version: 700
    cpe:2.3:a:sap:netweaver:700
  • Sap » Netweaver » Version: 701
    cpe:2.3:a:sap:netweaver:701
  • Sap » Netweaver » Version: 702
    cpe:2.3:a:sap:netweaver:702
  • Sap » Netweaver » Version: 707
    cpe:2.3:a:sap:netweaver:707
  • Sap » Netweaver » Version: 730
    cpe:2.3:a:sap:netweaver:730
  • Sap » Netweaver » Version: 731
    cpe:2.3:a:sap:netweaver:731
  • Sap » Netweaver » Version: 737
    cpe:2.3:a:sap:netweaver:737
  • Sap » Netweaver » Version: 740
    cpe:2.3:a:sap:netweaver:740
  • Sap » Netweaver » Version: 7400.12.21.30308
    cpe:2.3:a:sap:netweaver:7400.12.21.30308
  • Sap » Netweaver » Version: 747
    cpe:2.3:a:sap:netweaver:747
  • Sap » Netweaver » Version: 750
    cpe:2.3:a:sap:netweaver:750
  • Sap » Netweaver » Version: 751
    cpe:2.3:a:sap:netweaver:751
  • Sap » Netweaver » Version: 752
    cpe:2.3:a:sap:netweaver:752
  • Sap » Netweaver » Version: 753
    cpe:2.3:a:sap:netweaver:753
  • Sap » Netweaver » Version: 754
    cpe:2.3:a:sap:netweaver:754
  • Sap » Netweaver » Version: 755
    cpe:2.3:a:sap:netweaver:755
  • Sap » Netweaver » Version: 756
    cpe:2.3:a:sap:netweaver:756
  • Sap » Netweaver » Version: 757
    cpe:2.3:a:sap:netweaver:757
  • Sap » Netweaver » Version: 800
    cpe:2.3:a:sap:netweaver:800
  • Sap » Netweaver » Version: 802
    cpe:2.3:a:sap:netweaver:802
  • Sap » Netweaver » Version: 803
    cpe:2.3:a:sap:netweaver:803
  • Sap » Netweaver » Version: 804
    cpe:2.3:a:sap:netweaver:804
  • Sap » Netweaver » Version: 805
    cpe:2.3:a:sap:netweaver:805
  • Sap » Netweaver » Version: 806
    cpe:2.3:a:sap:netweaver:806
  • Sap » Netweaver » Version: 807
    cpe:2.3:a:sap:netweaver:807
  • Sap » Netweaver » Version: application_server_java
    cpe:2.3:a:sap:netweaver:application_server_java
  • Sap » Netweaver » Version: kernel_7.22
    cpe:2.3:a:sap:netweaver:kernel_7.22
  • Sap » Netweaver » Version: kernel_7.53
    cpe:2.3:a:sap:netweaver:kernel_7.53
  • Sap » Netweaver » Version: kernel_7.54
    cpe:2.3:a:sap:netweaver:kernel_7.54
  • Sap » Netweaver » Version: krnl64nuc_7.22
    cpe:2.3:a:sap:netweaver:krnl64nuc_7.22
  • Sap » Netweaver » Version: krnl64nuc_7.22ext
    cpe:2.3:a:sap:netweaver:krnl64nuc_7.22ext
  • Sap » Netweaver » Version: krnl64uc_7.22
    cpe:2.3:a:sap:netweaver:krnl64uc_7.22
  • Sap » Netweaver » Version: krnl64uc_7.22ext
    cpe:2.3:a:sap:netweaver:krnl64uc_7.22ext
  • Sap » Netweaver » Version: krnl64uc_7.53
    cpe:2.3:a:sap:netweaver:krnl64uc_7.53
  • Sap » Netweaver » Version: webdisp_7.22ext
    cpe:2.3:a:sap:netweaver:webdisp_7.22ext
  • Sap » Netweaver » Version: webdisp_7.53
    cpe:2.3:a:sap:netweaver:webdisp_7.53
  • Sap » Netweaver » Version: webdisp_7.54
    cpe:2.3:a:sap:netweaver:webdisp_7.54


Contact Us

Shodan ® - All rights reserved