CVE-2016-9562: SAP NetWeaver Application Server Java
High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.
Affected products
- SAP NetWeaver Application Server Java: version 7.40 only
Published 2016-11-23. Last modified 2026-06-17.