Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2jw-cxmg-w6mx

Опубликовано: 28 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

EPSS

Процентиль: 5%
0.0015
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

EPSS

Процентиль: 5%
0.0015
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-497