peter bassill · operator
$ cve CVE-2017-8852 JSON

CVE-2017-8852 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file. The vendor response is SAP Security Note 2441560.

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS3.3% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2017-05-10
Last modified2026-06-17

Affected (1)

VendorProduct
sapsapcar

Public exploits

SourceTitleDate
exploit-dbSAP SAPCAR 721.510 - Heap Buffer Overflow2017-05-10

References

→ the Explorer  ·  watch your stack  ·  NVD