Security Vulnerability in Self-Registration and Profile Modification in NetWeaver AS Java
CVE-2024-27899
Currently unrated
Summary
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
Get notified when SecurityVulnerability.io launches alerting 🔔
Well keep you posted 📧
News Articles
prophaze.comCVE-2024-27899
CVE-2024-27899 : SAP NETWEAVER AS JAVA USER MANAGEMENT ENGINE 7.50 USER ADMIN APPLICATION PASSWORD RECOVERY - Cloud WAF
CVE-2024-27899 : Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer.
9 months ago
References
Timeline
- 📰
First article discovered by prophaze.com
Vulnerability published