Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-3973

Опубликовано: 07 апр. 2016
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tcrtccoll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note 2255990.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:netweaver_application_server_java:*:*:*:*:*:*:*:*
Версия от 7.10 (включая) до 7.50 (включая)

EPSS

Процентиль: 66%
0.00503
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note 2255990.

EPSS

Процентиль: 66%
0.00503
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200