SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits. | |
| Title | Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-01-14T00:08:21.600Z
Updated: 2025-01-14T15:01:44.276Z
Reserved: 2024-12-05T21:37:23.093Z
Link: CVE-2025-0053
Updated: 2025-01-14T15:01:40.347Z
Status : Received
Published: 2025-01-14T01:15:15.403
Modified: 2025-01-14T01:15:15.403
Link: CVE-2025-0053
No data.