Описание
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
Ссылки
- Permissions Required
- Vendor Advisory
- Permissions Required
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sap:application_interface_framework:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:application_interface_framework:756:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00308
Низкий
3.1 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 4.3
github
почти 3 года назад
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
EPSS
Процентиль: 54%
0.00308
Низкий
3.1 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo