The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
2023-04-11T04:16:08.080
2024-11-21T07:56:34.237
Modified
CVSSv3.1: 3.1 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | application_interface_framework | 755 | Yes |
Application | sap | application_interface_framework | 756 | Yes |