CVE-2017-7696: SAP SSO Authentication Library

High severity, CVSS 7.5. EPSS: 36.2% chance of exploitation in the next 30 days.

SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042.

Affected products

  • SAP SSO Authentication Library: version 2.0 only; version 3.0 only

Published 2017-04-14. Last modified 2026-06-17.