Back

CVE-2013-1592

CRITICAL

A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.

Published: Jan 23, 2020 Modified: Jun 16, 2026
CWE-120

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
sap netweaver 7.01
sap netweaver 7.02
sap netweaver 7.30
sap netweaver 2004s

GitHub Security Advisory GHSA-24v7-wjmf-q732

A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics()...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 24.41%

Top 2% most likely to be exploited

Threat Score 46.5 / 100

Data Sources

NVD EPSS GitHub