CVE-2016-9562: SAP NetWeaver Application Server Java

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.

Affected products

  • SAP NetWeaver Application Server Java: version 7.40 only

Published 2016-11-23. Last modified 2026-06-17.