Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3428847 | Permissions Required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 | Vendor Advisory |
https://me.sap.com/notes/3428847 | Permissions Required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 | Vendor Advisory |
Configurations
History
07 Feb 2025, 17:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:netweaver_enterprise_portal:7.50:*:*:*:*:*:*:* | |
First Time |
Sap netweaver Enterprise Portal
Sap |
|
References | () https://me.sap.com/notes/3428847 - Permissions Required | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - Vendor Advisory |
Information
Published : 2024-03-12 01:15
Updated : 2025-02-07 17:24
NVD link : CVE-2024-25645
Mitre link : CVE-2024-25645
CVE.ORG link : CVE-2024-25645
JSON object : View
Products Affected
sap
- netweaver_enterprise_portal
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource