Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
2022-11-08T22:15:19.050
2024-11-21T07:22:50.457
Modified
CVSSv3.1: 4.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | netweaver_application_server_abap | 700 | Yes |
Application | sap | netweaver_application_server_abap | 731 | Yes |
Application | sap | netweaver_application_server_abap | 740 | Yes |
Application | sap | netweaver_application_server_abap | 750 | Yes |
Application | sap | netweaver_application_server_abap | 789 | Yes |
Application | sap | netweaver_application_server_abap | 804 | Yes |