SAP NetWeaver AS for Java Vulnerability Allows Access to Sensitive Information

CVE-2024-45283
6MEDIUM

Key Information

Vendor
SAP
Status
SAP Netweaver As For Java (destination Service)
Vendor
CVE Published:
10 September 2024

Summary

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

Affected Version(s)

SAP NetWeaver AS for Java (Destination Service) = 7.50

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.