CVE-2017-14581: SAP NetWeaver Application Server Java

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181.

Affected products

  • SAP NetWeaver Application Server Java: from 7.00, up to and including 7.50

Published 2017-09-19. Last modified 2026-06-17.