CVE-2017-5372: SAP NetWeaver

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.

Affected products

  • SAP NetWeaver: any version

Published 2017-01-23. Last modified 2026-06-17.