CVE-2016-10304 describes a denial-of-service vulnerability in the SAP EP-RUNTIME component of SAP NetWeaver AS JAVA 7.5. Authenticated remote attackers can exploit this by submitting a specially crafted serialized Java object, leading to out-of-memory errors and service instability. With a CVSS score of 6.5 (Medium), this vulnerability requires authenticated access but has low attack complexity, potentially causing high impact to availability. There is no known public exploit code (Metasploit, Nuclei, ExploitDB), and it shows minimal community discussion or media coverage, suggesting it is not actively exploited or widely discussed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.50CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.