CVE-2016-3979
Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the IctParseCookies function, aka SAP Security Note 2256185.
- Affected products
- Sap As Java
- Sap Java As
- = 7.4
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 6.4% (93th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2016-04-08
CVE-2016-3979 at NVD
1 known exploit for CVE-2016-3979
Proof-of-concept code and exploit modules indexed by Sploitus