Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-9844

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or flooding the service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.057
EPSS Ranking 90.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.5
Products affected by CVE-2017-9844
  • Sap » Netweaver » Version: 7400.12.21.30308
    cpe:2.3:a:sap:netweaver:7400.12.21.30308


Contact Us

Shodan ® - All rights reserved