### [CVE-2017-9843](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9843) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841. ### POC #### Reference - https://erpscan.io/advisories/erpscan-17-010-sap-netweaver-abap-dispwork-crash-using-cl_java_script/ #### Github - https://github.com/Hwangtaewon/radamsa - https://github.com/StephenHaruna/RADAMSA - https://github.com/nqwang/radamsa - https://github.com/sambacha/mirror-radamsa - https://github.com/sunzu94/radamsa-Fuzzer - https://github.com/vah13/SAP_vulnerabilities