Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47593

Опубликовано: 12 нояб. 2024
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.

EPSS

Процентиль: 37%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 4.3
github
около 1 года назад

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.

CVSS3: 4.3
fstec
около 1 года назад

Уязвимость сервера веб-приложений SAP NetWeaver Java Application Server, связанная с некорректно используемыми стандартными разрешениями, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 37%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-276