SAP NetWeaver AS for Java Vulnerability Allows Access to Sensitive Information
CVE-2024-45283
6MEDIUM
Key Information
- Vendor
- SAP
- Status
- SAP Netweaver As For Java (destination Service)
- Vendor
- CVE Published:
- 10 September 2024
Summary
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.
Affected Version(s)
SAP NetWeaver AS for Java (Destination Service) = 7.50
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database