Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3428847 | Permissions Required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 | Vendor Advisory |
https://me.sap.com/notes/3428847 | Permissions Required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 | Vendor Advisory |
Configurations
History
07 Feb 2025, 17:24
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sap
Sap netweaver Enterprise Portal |
|
CPE | cpe:2.3:a:sap:netweaver_enterprise_portal:7.50:*:*:*:*:*:*:* | |
References | () https://me.sap.com/notes/3428847 - Permissions Required | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - Vendor Advisory |
21 Nov 2024, 09:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://me.sap.com/notes/3428847 - | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - |
28 Sep 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application. | |
CWE | CWE-732 |
12 Mar 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-12 01:15
Updated : 2025-02-07 17:24
NVD link : CVE-2024-25645
Mitre link : CVE-2024-25645
CVE.ORG link : CVE-2024-25645
JSON object : View
Products Affected
sap
- netweaver_enterprise_portal
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource