Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3428847 | Permissions Required |
| https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 | Vendor Advisory |
| https://me.sap.com/notes/3428847 | Permissions Required |
| https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-03-12 01:15
Updated : 2025-02-07 17:24
NVD link : CVE-2024-25645
Mitre link : CVE-2024-25645
CVE.ORG link : CVE-2024-25645
JSON object : View
Products Affected
sap
- netweaver_enterprise_portal
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
