« Volver al listado

CVE-2016-10311

Estado: ModificadaCrítica (9.8)—

Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-10311",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-10T15:59:00.300",
  "references": [
    {
      "url": "https://erpscan.io/advisories/erpscan-16-030-sap-netweaver-sapstartsrv-stack-based-buffer-overflow/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://erpscan.io/advisories/erpscan-16-030-sap-netweaver-sapstartsrv-stack-based-buffer-overflow/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238."
    },
    {
      "lang": "es",
      "value": "El desbordamiento de búfer basado en pila en SAP NetWeaver desde 7.0 hasta la versión 7.5 permite a atacantes remotos causar una denegación de servicio () enviando un paquete manipulado al puerto SAPSTARTSRV, también conocido como Nota de seguridad de SAP 2295238."
    }
  ],
  "lastModified": "2026-06-17T00:39:27.543",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41FAC5DD-D577-47F9-B0CA-006032256642"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.0:ehp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FC1767F-10BD-468B-8D2B-538C82EB69B2"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.0:ehp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D04DC424-129B-448D-994B-7AC5D9B64703"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.0:ehp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D9A5776-17A4-4ECD-8D2B-57D21BB16FF7"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "903CA9A5-1348-4A77-979E-2A2EB15722EA"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.3:ehp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CD7B893-F184-4F2A-BD23-B1D107D68A15"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20754323-2EF6-4726-B34B-354F9C352A56"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74F7C92A-48F7-456A-BDFF-91A482DE8546"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}