CVE-2017-5997: SAP Kernel

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash) via multiple msgserver/group?group= requests with a crafted size of the group parameter, aka SAP Security Note 2358972.

Affected products

  • SAP SAP Kernel: version 7.21 only; version 7.22 only; version 7.42 only

Published 2017-02-15. Last modified 2026-06-17.