Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-556c-jfj4-29vc

Опубликовано: 09 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.

Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.

EPSS

Процентиль: 31%
0.0012
Низкий

8.8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.

CVSS3: 8.8
fstec
почти 2 года назад

Уязвимость компонента User Admin Application программного средства создания и развертывания веб-приложений SAP NetWeaver AS for Java, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 31%
0.0012
Низкий

8.8 High

CVSS3

Дефекты

CWE-640