SAP NetWeaver AS for Java Vulnerability Allows Access to Sensitive Information
CVE-2024-45283

6MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 September 2024

Summary

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

Affected Version(s)

SAP NetWeaver AS for Java (Destination Service) 7.50

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.