CVE-2016-3980: SAP Application Server Java

High severity, CVSS 7.5. EPSS: 7.1% chance of exploitation in the next 30 days.

The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547.

Affected products

  • SAP Application Server Java: from 7.2, up to and including 7.4

Published 2016-04-08. Last modified 2026-06-17.