Vulnerability report

Exploited in the wild High confidence Not in CISA KEV

CVE-2017-9844

NetWeaver Denial of Service

SAP / NetWeaver

Severity
CVSS 7.5 · High
Confidence
High
Exploit status
Exploited in the wild
EPSS
5.5%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2017-9844 is an unauthenticated vulnerability affecting SAP NetWeaver. SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted...

Is it exploited?

Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is high.

Who is affected?

SAP / NetWeaver.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

NetWeaver Denial of Service

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804.

Published
12 Jul 2017
Exploitation Reported
01 May 2025
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

java

KEV Intelligence Analysis Notes

Analyst-curated context on exploitation evidence and operational relevance.

test

CVE References

Exploitation evidence

Why KEV Intelligence marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Tenable Blog

Recorded 01 May 2025

Independent exploitation attestation added to the KEV Intelligence record.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.

Learn about Pro API access
Source Added
Tenable Blog First 2025-05-01 08:57 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
0
User-Agents
0

Raw values available in Pro and Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

7.5 High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

5.5%

Recent mention · Tenable Blog

CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild

SAP has released out-of-band patch to address CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver that has been exploited by threat actors. Organizations are strongly encouraged to apply patches as soon as possible.BackgroundOn April 22, ReliaQuest published...

Read full advisory

All CVSS Scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2.0 7.5 High

AV:N/AC:L/Au:N/C:P/I:P/A:P

All Mentions

Recent mention · Tenable Blog

CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild

Tenable Blog · 25 Apr 2025

SAP has released out-of-band patch to address CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver that has been exploited by threat actors. Organizations are strongly encouraged to apply patches as soon as possible.BackgroundOn April 22, ReliaQuest published details of their investigation of exploit activity in SAP NetWeaver servers. Initially it was unclear if their discovery was a new vulnerability or the abuse of CVE-2017-9844, a vulnerability that could lead to a denial-of-service (DoS) condition or arbitrary code execution. ReliaQuest reported their findings to SAP and...

Recent mention · TheHackerNews

New Critical SAP NetWeaver Flaw Exploited to Drop Web Shell, Brute Ratel Framework

TheHackerNews · 25 Apr 2025

Threat actors are likely exploiting a new vulnerability in SAP NetWeaver to upload JSP web shells with the goal of facilitating unauthorized file uploads and code execution.  "The exploitation is likely tied to either a previously disclosed vulnerability like CVE-2017-9844 or an unreported remote file inclusion (RFI) issue," ReliaQuest said in a report published this week. The cybersecurity

Timeline

From disclosure to observed exploitation

  1. Added to KEV Intelligence KEV Feed

    High-confidence, third-party attested exploitation

  2. CVE published

    Vulnerability disclosed publicly

  3. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2017-9844

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2017-9844",
  "confidence": "High",
  "cvss_score": 7.5,
  "cvss_estimated": false,
  "epss_score": 0.05513,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.