Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c76-qm2v-h37j

Опубликовано: 11 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.

EPSS

Процентиль: 48%
0.00251
Низкий

8.6 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.6
nvd
6 месяцев назад

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.

EPSS

Процентиль: 48%
0.00251
Низкий

8.6 High

CVSS3

Дефекты

CWE-22