Vulnerability Description
Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted requests, aka SAP Security Note 2330422.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sybase | Adaptive Server Enterprise | 16.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/140610/SAP-ASE-ODATA-Server-16-Denial-Of-SeThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Jan/47Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93545Third Party AdvisoryVDB Entry
- https://erpscan.io/advisories/erpscan-16-036-sap-ase-odata-server-denial-service
- https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-octobe
- http://packetstormsecurity.com/files/140610/SAP-ASE-ODATA-Server-16-Denial-Of-SeThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Jan/47Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93545Third Party AdvisoryVDB Entry
- https://erpscan.io/advisories/erpscan-16-036-sap-ase-odata-server-denial-service
- https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-octobe
FAQ
What is CVE-2017-5371?
CVE-2017-5371 is a vulnerability with a CVSS score of 7.5 (HIGH). Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted requests, aka SAP Security Note 2330422.
How severe is CVE-2017-5371?
CVE-2017-5371 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5371?
Check the references section above for vendor advisories and patch information. Affected products include: Sybase Adaptive Server Enterprise.