Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-464f-pfvj-h8rq

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication.  A subsequent call to one of these methods can read or change the state of existing services without any effect on availability.

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication.  A subsequent call to one of these methods can read or change the state of existing services without any effect on availability.

EPSS

Процентиль: 52%
0.00293
Низкий

8.2 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.2
nvd
больше 2 лет назад

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication.  A subsequent call to one of these methods can read or change the state of existing services without any effect on availability.

CVSS3: 9.1
fstec
почти 3 года назад

Уязвимость программного средства создания и развертывания веб-приложений SAP AS NetWeaver JAVA, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю изменять состояние существующих служб

EPSS

Процентиль: 52%
0.00293
Низкий

8.2 High

CVSS3

Дефекты

CWE-306