Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3rg-6v2h-rjpj

Опубликовано: 13 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

EPSS

Процентиль: 25%
0.00085
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость программных интеграционных платформ SAP NetWeaver AS ABAP, SAP NetWeaver AS for Java, сервера содержимого SAP Content Server и веб-диспетчера SAP Web Dispatcher, связанная с недостатками процедуры авторизации, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 25%
0.00085
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-862