Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)
CVE-2023-29111

3.1LOW

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 April 2023

What is CVE-2023-29111?

The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.

Affected Version(s)

Application Interface Framework (ODATA service) 755

Application Interface Framework (ODATA service) 756

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.