CVE-2017-8852 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file. The vendor response is SAP Security Note 2441560.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 3.3% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-05-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | sapcar |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SAP SAPCAR 721.510 - Heap Buffer Overflow | 2017-05-10 |
References
- http://www.securityfocus.com/bid/98350
- https://www.coresecurity.com/advisories/sap-sapcar-heap-based-buffer-overflow-vulnerability
- https://www.exploit-db.com/exploits/41991/
- http://www.securityfocus.com/bid/98350
- https://www.coresecurity.com/advisories/sap-sapcar-heap-based-buffer-overflow-vulnerability
- https://www.exploit-db.com/exploits/41991/
→ the Explorer · watch your stack · NVD