Patch Day SAP: Crafted Network Request Paves Way for Crashes
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
Heise reports on SAP patch day with multiple critical vulnerabilities but does not name active attacks or exploit code; typical patch reminder reporting without evidence of wild exploitation.
Description
SAP releases critical security updates for SAP NetWeaver and SAP Extended Passport. Vulnerabilities are triggered by crafted network requests and enable denial-of-service conditions. The exact nature of the flaws (remote code execution vs. DoS only) and scope of affected versions are not detailed in the Heise report. No evidence of active exploitation or public exploits is provided.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational