{"api_version":"1","generated_at":"2026-07-23T10:18:36+00:00","cve":"CVE-2009-4603","urls":{"html":"https://cve.report/CVE-2009-4603","api":"https://cve.report/api/cve/CVE-2009-4603.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4603","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4603"},"summary":{"title":"CVE-2009-4603","description":"Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console shutdown) via a crafted request. NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-01-12 17:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://service.sap.com/sap/support/notes/1302231","name":"https://service.sap.com/sap/support/notes/1302231","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securitytracker.com/id?1023319","name":"http://www.securitytracker.com/id?1023319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - SAP sapstartsrv Bug Lets Remote Users Deny Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37684","name":"http://secunia.com/advisories/37684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SAP Products \"sapstartsrv\" Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf","name":"http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/37286","name":"http://www.securityfocus.com/bid/37286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SAP Kernel 'sapstartsrv' Denial Of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4603","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4603","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_kernel","cpe6":"6.40","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_kernel","cpe6":"7.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_kernel","cpe6":"7.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_kernel","cpe6":"7.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_kernel","cpe6":"7.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_kernel","cpe6":"7.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_netweaver","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"4603","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"sap_web_application_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:08:37.961Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1023319","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023319"},{"name":"37684","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37684"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://service.sap.com/sap/support/notes/1302231"},{"name":"37286","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/37286"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console shutdown) via a crafted request. NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-01-12T17:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1023319","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023319"},{"name":"37684","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37684"},{"tags":["x_refsource_MISC"],"url":"http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf"},{"tags":["x_refsource_MISC"],"url":"https://service.sap.com/sap/support/notes/1302231"},{"name":"37286","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/37286"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-4603","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console shutdown) via a crafted request. NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1023319","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1023319"},{"name":"37684","refsource":"SECUNIA","url":"http://secunia.com/advisories/37684"},{"name":"http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf","refsource":"MISC","url":"http://www.cybsec.com/vuln/CYBSEC_SAP_sapstartsrv_DoS.pdf"},{"name":"https://service.sap.com/sap/support/notes/1302231","refsource":"MISC","url":"https://service.sap.com/sap/support/notes/1302231"},{"name":"37286","refsource":"BID","url":"http://www.securityfocus.com/bid/37286"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-4603","datePublished":"2010-01-12T17:00:00.000Z","dateReserved":"2010-01-12T00:00:00.000Z","dateUpdated":"2024-09-16T22:56:36.552Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-01-12 17:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_kernel:6.40:*:*:*:*:*:*:*","matchCriteriaId":"548D937D-FF7F-4B5B-98A2-50F5FBA7875D"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_kernel:7.00:*:*:*:*:*:*:*","matchCriteriaId":"DA732B51-EF58-41D1-A012-195847AE9CC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_kernel:7.01:*:*:*:*:*:*:*","matchCriteriaId":"78E8D3B9-CAF2-47FD-93C7-CCF6554BBA49"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_kernel:7.10:*:*:*:*:*:*:*","matchCriteriaId":"9B8965F9-F10A-4F6A-830C-7D5D4596AA26"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_kernel:7.11:*:*:*:*:*:*:*","matchCriteriaId":"B09614D3-0B53-48FC-9E1F-05384AEFBE57"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:sap_kernel:7.20:*:*:*:*:*:*:*","matchCriteriaId":"633CC2AD-4B48-4473-A818-93E40DCBEFBE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:sap:sap_netweaver:7.0:*:*:*:*:*:*:*","matchCriteriaId":"813CC383-4123-45B0-A58A-78A8DC71FFE7"},{"vulnerable":false,"criteria":"cpe:2.3:a:sap:sap_web_application_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"FC17AFFF-324D-40F5-9305-1A049E16B7A3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4603","Ordinal":"1","Title":"CVE-2009-4603","CVE":"CVE-2009-4603","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4603","Ordinal":"1","NoteData":"Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console shutdown) via a crafted request. NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2009-4603"},{"CveYear":"2009","CveId":"4603","Ordinal":"2","NoteData":"2010-01-12","Type":"Other","Title":"Published"}]}}}