Information Disclosure Vulnerability in SAP NetWeaver Application Server for Java
CVE-2019-0318
5.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 July 2019
Summary
SAP NetWeaver Application Server for Java, in specific versions, contains a flaw that could enable an attacker to gain unauthorized access to sensitive information that is otherwise intended to be restricted. This vulnerability arises from improper handling of input, potentially allowing external entities to retrieve data that may compromise system integrity or user confidentiality.
Affected Version(s)
SAP NetWeaver Application Server for Java (Startup Framework) < 7.21 < 7.21
SAP NetWeaver Application Server for Java (Startup Framework) < 7.22 < 7.22
SAP NetWeaver Application Server for Java (Startup Framework) < 7.45 < 7.45
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved