peter bassill · operator
$ cve CVE-2011-1517 JSON

CVE-2011-1517

9.8
CRITICAL · CVSS 3.1 · EPSS 4.2% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.22% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploitnone known
Published2020-02-05
Last modified2026-06-16

Affected (1)

VendorProduct
sapnetweaver

References

→ the Explorer  ·  watch your stack  ·  NVD