Description
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.
Problem types
CWE-476: NULL Pointer Dereference
Product status
KRNL64NUC 7.22
7.22EXT
KRNL64UC 7.22
7.53
KERNEL 7.22
7.54
7.77
7.89
7.93
9.14
9.15
9.16