Impact
The SAPSPrint Service has a memory corruption bug that allows an unauthenticated attacker to send crafted requests that overflow a buffer. The overflow triggers a crash and an automatic restart, causing a temporary pause in service availability. The vulnerability does not compromise confidentiality or integrity, and it is classified under CWE‑121. The impact is mainly a short‑lived denial of service.
Affected Systems
The flaw affects SAP's SAPSPrint Service. No specific version information is listed in the CNA data. Organizations using this service should verify whether their deployments are impacted by checking the referenced SAP Note or contacting SAP support.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Because the EPSS score is unavailable and the issue is not in a CISA KEV catalog, the likelihood of widespread exploitation is unclear. The attack vector is inferred to be remote, as the attacker sends traffic over the network, and authentication is not required. While the service interruption is brief, repeated exploitation could degrade user experience.
OpenCVE Enrichment